XSS Vulnerability in Ivan Cordoba Generic Content Management System
CVE-2018-20590

4.8MEDIUM

What is CVE-2018-20590?

An XSS vulnerability exists in the Ivan Cordoba Generic Content Management System. Through the user ID in the Administrator/users.php file, an attacker could potentially exploit this weakness, compromising the security and integrity of the affected systems. This vulnerability highlights the importance of implementing secure coding practices to protect against unauthorized access and malicious attacks.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.