Stored XSS in WUZHI CMS Affects Web Applications
CVE-2018-18938
4.8MEDIUM
What is CVE-2018-18938?
A stored XSS vulnerability exists in WUZHI CMS 4.1.0, specifically at index.php?m=core&f=index. The issue arises from an unvalidated ontoggle attribute within a second input field, allowing attackers to inject malicious scripts that are stored on the server and executed in the context of other users' sessions. This vulnerability can lead to unauthorized actions, data theft, and further exploitation of the web application's security.