Stored Cross-Site Scripting Vulnerability in REDAXO Media Pool
CVE-2018-18198
6.1MEDIUM
What is CVE-2018-18198?
A stored XSS vulnerability exists in the REDAXO Media Pool, specifically in the handling of the $opener_input_field variable within addons/mediapool/pages/index.php. This vulnerability allows attackers to inject malicious XSS payloads through a crafted request to index.php?page=mediapool/media&opener_input_field=[XSS]. If exploited, this security flaw could allow attackers to execute arbitrary scripts within the context of the user's browser, potentially compromising the confidentiality and integrity of data.