Cross-Site Scripting Vulnerability in Wolf CMS by WolfCMS
CVE-2018-6890
4.8MEDIUM
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2018-6890?
A Cross-Site Scripting (XSS) vulnerability exists in Wolf CMS version 0.8.3.1, allowing attackers to inject malicious scripts via the page editing feature. This can lead to unauthorized actions performed on behalf of the user and can potentially compromise sensitive user data. The vulnerability can be triggered by manipulating the admin page edit URL. It is crucial for users of this version to apply the necessary security updates.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
