Cross-Site Scripting Vulnerability in WUZHI CMS by WUZHI Technology
CVE-2018-17832
6.1MEDIUM
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2018-17832?
An XSS vulnerability in WUZHI CMS 2.0 can be exploited through unsanitized input in the index.php file, specifically via the 'v' or 'f' parameters. This allows attackers to inject malicious scripts into web pages viewed by users, potentially leading to unauthorized actions and data theft. It is crucial for users of WUZHI CMS to implement necessary security measures and patch the vulnerability to mitigate risks. Refer to additional resources for exploit details and remediation strategies.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
