CVE-2018-10313: XSS
Published Apr 24, 2018
·Updated
WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq10%5D parameter to the /index.php?m=member&f=index&v=profile&setiframe=1 URI.
Affected Software
2 affected components
Wuzhicms Wuzhi Cms=4.1.0
Wuzhicms Wuzhicms=4.1.0
Event History
Apr 24, 2018
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·02:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-10313.
2
What is the severity of CVE-2018-10313?
The severity of CVE-2018-10313 is medium.
3
What software version is affected by CVE-2018-10313?
WUZHI CMS version 4.1.0 is affected by CVE-2018-10313.
4
How can an attacker exploit CVE-2018-10313?
An attacker can exploit CVE-2018-10313 by sending a malicious payload through the "form[qq_10]" parameter to the /index.php?m=member&f=index&v=profile&set_iframe=1 URI.
5
Are there any known fixes or patches for CVE-2018-10313?
There are no known fixes or patches for CVE-2018-10313 at the moment. It is recommended to update to a newer version of WUZHI CMS if available, or apply any security recommendations from the vendor.