First published: Tue Jul 10 2018(Updated: )
An issue was discovered in idreamsoft iCMS 7.0.9. XSS exists via the callback parameter in a public/api.php uploadpic request, bypassing the iWAF protection mechanism.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iCMS | =7.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue in idreamsoft iCMS 7.0.9 is CVE-2018-13865.
CVE-2018-13865 has a severity rating of 6.1, which is classified as medium.
The XSS vulnerability occurs via the callback parameter in a public/api.php uploadpic request, bypassing the iWAF protection mechanism.
CVE-2018-13865 affects idreamsoft iCMS version 7.0.9.
At the moment, there is no known fix for CVE-2018-13865 in idreamsoft iCMS 7.0.9. It is recommended to stay updated with the vendor's security advisories.