Cross-Site Scripting Vulnerability in WolfCMS by Wolf Software
CVE-2018-18823
4.8MEDIUM
What is CVE-2018-18823?
WolfCMS version 0.8.3.1 is susceptible to a Cross-Site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts via SVG files. This flaw is exploited through the file manager interface, specifically at the admin's file browsing functionality. When an administrator uploads an SVG file, the vulnerability permits executing arbitrary JavaScript code within the user’s browser, posing significant security risks.
