First published: Mon Aug 20 2018(Updated: )
MiniCMS version 1.1 contains a Cross Site Scripting (XSS) vulnerability in http://example.org/mc-admin/page.php?date={payload} that can result in code injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
1234n Minicms | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000638 is a Cross Site Scripting (XSS) vulnerability found in MiniCMS version 1.1.
CVE-2018-1000638 has a severity level of medium with a CVSS score of 6.1.
The affected software is MiniCMS version 1.1.
CVE-2018-1000638 allows an attacker to inject malicious code through the date parameter in the URL of the MiniCMS admin page.
To fix CVE-2018-1000638, update MiniCMS to a version that includes a patch for this vulnerability.