Stored XSS Vulnerability in WUZHI CMS by WUZHI
CVE-2018-18939
4.8MEDIUM
What is CVE-2018-18939?
An issue was identified in WUZHI CMS version 4.1.0 that allows for stored Cross-Site Scripting (XSS) attacks through a vulnerable seventh input field in the index.php?m=core&f=index endpoint. This vulnerability could potentially enable the execution of arbitrary scripts in the context of the user’s session, jeopardizing user data and the integrity of the application.