Stored XSS Vulnerability in JPress by JPressProjects
CVE-2018-19170
4.8MEDIUM
What is CVE-2018-19170?
In JPress version 1.0-rc.5, a vulnerability allows for stored Cross-Site Scripting (XSS) through manipulation of input fields within the admin settings interface. This vulnerability can be exploited via the 'web_name' parameter, potentially compromising the security of the web application and exposing sensitive user data. It is crucial for administrators to apply security measures to mitigate the risk of such attacks.