Cross-Site Scripting Vulnerability in Wolf CMS by Wolf CMS
CVE-2019-10646

6.1MEDIUM

Key Information:

Vendor

Wolfcms

Status
Vendor
CVE Published:
30 March 2019

What is CVE-2019-10646?

Wolf CMS v0.8.3.1 is vulnerable to a Cross-Site Scripting (XSS) flaw in the Add Snippet module. This vulnerability allows attackers to inject arbitrary JavaScript code via user input, which is executed when the affected snippet is accessed. This could lead to a range of attacks, including data theft and user session hijacking, putting the integrity and confidentiality of user data at risk.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.