First published: Thu Apr 19 2018(Updated: )
MiniCMS v1.10 has XSS via the mc-admin/conf.php site_link parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
1234n Minicms | =1.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10227 is a vulnerability in MiniCMS v1.10 that allows for cross-site scripting (XSS) attacks via the mc-admin/conf.php site_link parameter.
The severity of CVE-2018-10227 is medium with a CVSS score of 5.4.
CVE-2018-10227 affects MiniCMS v1.10 by allowing attackers to perform XSS attacks through the mc-admin/conf.php site_link parameter.
Yes, there is a fix for CVE-2018-10227. It is recommended to update MiniCMS to a version that includes the fix.
You can find more information about CVE-2018-10227 at the following reference: https://github.com/bg5sbk/MiniCMS/issues/15