CVE-2018-10311: XSS
Published Apr 24, 2018
·Updated
A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the tag[pinyin] parameter to the /index.php?m=tags&f=index&v=add URI.
Affected Software
2 affected components
Wuzhicms Wuzhi Cms=4.1.0
Wuzhicms Wuzhicms=4.1.0
Event History
Apr 24, 2018
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·02:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-10311?
The severity of CVE-2018-10311 is medium with a CVSS score of 6.1.
2
How does CVE-2018-10311 affect WUZHI CMS?
CVE-2018-10311 affects WUZHI CMS version 4.1.0.
3
What is the impact of CVE-2018-10311?
CVE-2018-10311 allows remote attackers to inject arbitrary web script or HTML leading to persistent cross-site scripting (XSS) vulnerabilities.
4
How can the XSS vulnerability in WUZHI CMS be exploited?
The XSS vulnerability in WUZHI CMS can be exploited by injecting malicious web scripts or HTML code through the tag[pinyin] parameter in the /index.php?m=tags&f=index&v=add URI.
5
Is there a fix available for CVE-2018-10311?
Yes, please update WUZHI CMS to version 4.1.1 or later to fix CVE-2018-10311.