First published: Fri Nov 17 2017(Updated: )
WBCE v1.1.11 is vulnerable to reflected XSS via the "begriff" POST parameter in /admin/admintools/tool.php?tool=user_search
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wbce CMS | =1.1.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Vulnerability CVE-2017-1000213 refers to a reflected cross-site scripting (XSS) vulnerability in WBCE v1.1.11.
An attacker can exploit CVE-2017-1000213 by injecting malicious JavaScript code into the "begriff" POST parameter in /admin/admintools/tool.php?tool=user_search.
Version 1.1.11 of WBCE CMS is affected by CVE-2017-1000213.
CVE-2017-1000213 has a severity rating of medium (4.8) according to the Common Vulnerability Scoring System (CVSS).
Yes, a fix has been implemented in the following commit: https://github.com/WBCE/WBCE_CMS/commit/0da620016aec17ac2d2f3a22c55ab8c2b55e691e#diff-7b380285e285160d0070863099baabe0