CVE-2018-11549: XSS
An issue was discovered in WUZHI CMS 4.1.0 There is a Stored XSS Vulnerability in "Account Settings -> Member Centre -> Chinese information -> Ordinary member" via a QQ number, as demonstrated by a form[qq10]= substring.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11549?
The severity of CVE-2018-11549 is medium (5.4).
How does the vulnerability in WUZHI CMS 4.1.0 work?
The vulnerability in WUZHI CMS 4.1.0 allows an attacker to perform a stored XSS attack through the Account Settings -> Member Centre -> Chinese information -> Ordinary member section by exploiting a QQ number field.
How can I fix the stored XSS vulnerability in WUZHI CMS 4.1.0?
To fix the stored XSS vulnerability in WUZHI CMS 4.1.0, it is recommended to update to a patched version of the CMS as soon as it becomes available.
Where can I find more details about CVE-2018-11549?
You can find more details about CVE-2018-11549 on the GitHub issue page: https://github.com/wuzhicms/wuzhicms/issues/139
What is the CWE classification of CVE-2018-11549?
The CWE classification of CVE-2018-11549 is CWE-79 (Cross-site Scripting).