CVE-2018-10298: XSS
Published Apr 22, 2018
·Updated
Discuz! DiscuzX through X3.4 has reflected XSS via forum.php?mod=post&action=newthread because data/template/1diyportalview.tpl.php does not restrict the content.
Affected Software
1 affected component
Discuz DiscuzX<=x3.4
Event History
Apr 22, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-10298?
The severity of CVE-2018-10298 is classified as high due to its potential for reflected XSS attacks.
2
How do I fix CVE-2018-10298?
To fix CVE-2018-10298, update to the latest version of Discuz! DiscuzX that contains patches for this vulnerability.
3
What type of vulnerability is CVE-2018-10298?
CVE-2018-10298 is a reflected Cross-Site Scripting (XSS) vulnerability.
4
Which versions are affected by CVE-2018-10298?
CVE-2018-10298 affects Discuz! DiscuzX versions up to and including X3.4.
5
What is the impact of exploiting CVE-2018-10298?
Exploiting CVE-2018-10298 can allow attackers to inject malicious scripts into web pages viewed by users, potentially compromising user accounts.