Cross-Site Scripting Vulnerability in Discuz! X3.4 by Discuz
CVE-2018-5376
6.1MEDIUM
What is CVE-2018-5376?
Discuz! X3.4 contains a Cross-Site Scripting (XSS) vulnerability through the op parameter in the include\spacecp\spacecp_upload.php file. This flaw can allow an attacker to inject malicious scripts into web pages viewed by users, potentially compromising the security of affected systems and facilitating unauthorized actions.
