Cross-Site Scripting Vulnerability in WolfCMS by Wolf Software
CVE-2018-18823

4.8MEDIUM

Key Information:

Vendor

Wolfcms

Status
Vendor
CVE Published:
25 April 2019

What is CVE-2018-18823?

WolfCMS version 0.8.3.1 is susceptible to a Cross-Site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts via SVG files. This flaw is exploited through the file manager interface, specifically at the admin's file browsing functionality. When an administrator uploads an SVG file, the vulnerability permits executing arbitrary JavaScript code within the user’s browser, posing significant security risks.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.