CVE-2018-10368: XSS
Published Apr 25, 2018
·Updated
An issue was discovered in WUZHI CMS 4.1.0. The "Extension Module -> System Announcement" feature has Stored XSS via an announcement.
Affected Software
2 affected components
Wuzhicms Wuzhi Cms=4.1.0
Wuzhicms Wuzhicms=4.1.0
Event History
Apr 25, 2018
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Data Sourced
via NVD·09:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-10368.
2
What is the severity rating of CVE-2018-10368?
CVE-2018-10368 has a severity rating of medium (4.8).
3
What software version is affected by CVE-2018-10368?
CVE-2018-10368 affects WUZHI CMS version 4.1.0.
4
What is the CWE ID associated with CVE-2018-10368?
The CWE ID associated with CVE-2018-10368 is CWE-79 (Cross-Site Scripting).
5
Is there a patch or fix available for CVE-2018-10368?
Please refer to the official reference for information on any available patches or fixes for CVE-2018-10368.