Cross-Site Scripting Vulnerability in Ivan Cordoba Generic Content Management System
CVE-2018-20589
4.8MEDIUM
Key Information:
- Vendor
- CVE Published:
- 30 December 2018
What is CVE-2018-20589?
The Ivan Cordoba Generic Content Management System prior to April 28, 2018, is susceptible to a cross-site scripting attack via the 'Administrator/add_pictures.php' endpoint, specifically through manipulation of the article ID parameter. This flaw can allow attackers to inject malicious scripts into web pages viewed by users, potentially compromising sensitive information and user interactions.
