Cross-Site Scripting Vulnerability in WUZHI CMS by WUZHI Technology
CVE-2018-17832

6.1MEDIUM

Key Information:

Vendor

Wuzhicms

Status
Vendor
CVE Published:
1 October 2018

What is CVE-2018-17832?

An XSS vulnerability in WUZHI CMS 2.0 can be exploited through unsanitized input in the index.php file, specifically via the 'v' or 'f' parameters. This allows attackers to inject malicious scripts into web pages viewed by users, potentially leading to unauthorized actions and data theft. It is crucial for users of WUZHI CMS to implement necessary security measures and patch the vulnerability to mitigate risks. Refer to additional resources for exploit details and remediation strategies.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.