CVE-2018-10297: XSS
Discuz! DiscuzX through X3.4 has stored XSS via the portal.php?mod=portalcp&ac=article URI, related to mishandling of IMG elements associated with remote images.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-10297?
CVE-2018-10297 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting attacks.
How does CVE-2018-10297 exploit stored XSS?
CVE-2018-10297 exploits stored XSS by mishandling IMG elements within the portal.php?mod=portalcp&ac=article URI allowing attackers to inject malicious scripts.
Which versions of Discuz! are affected by CVE-2018-10297?
CVE-2018-10297 affects all versions of Discuz! DiscuzX up to and including version X3.4.
How do I mitigate CVE-2018-10297?
To mitigate CVE-2018-10297, users should upgrade to a patched version of Discuz! that addresses this stored XSS vulnerability.
Can CVE-2018-10297 affect user data?
Yes, CVE-2018-10297 can compromise user data by allowing attackers to execute scripts that steal cookies or session tokens.