CVE-2018-13849: XSS
Published Jul 10, 2018
·Updated
editrequests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequate XSS protection mechanism based on pregreplace.
Affected Software
1 affected component
Instagram-clone Project Instagram-clone<=2018-04-23
Event History
Jul 10, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-13849?
CVE-2018-13849 has a medium severity rating due to its XSS vulnerability.
2
How do I fix CVE-2018-13849?
To fix CVE-2018-13849, update your yTakkar Instagram-clone to a version released after April 23, 2018.
3
What does CVE-2018-13849 exploit?
CVE-2018-13849 exploits an inadequate XSS protection mechanism in the edit_requests.php file.
4
Which versions of Instagram-clone are affected by CVE-2018-13849?
All versions of Instagram-clone up to and including 2018-04-23 are affected by CVE-2018-13849.
5
What type of attack can CVE-2018-13849 lead to?
CVE-2018-13849 can lead to cross-site scripting (XSS) attacks via an onmouseover payload.