CVE-2018-13983: XSS
ImpressCMS 1.3.10 has XSS via the PATHINFO to htdocs/install/index.php, htdocs/install/pagelangselect.php, or htdocs/install/pagemodcheck.php.
Other sources
ImpressCMS 1.3.10 has XSS via the PATHINFO to htdocs/install/index.php, htdocs/install/pagelangselect.php, or htdocs/install/pagemodcheck.php.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-13983?
CVE-2018-13983 is a vulnerability in ImpressCMS 1.3.10 that allows cross-site scripting (XSS) attacks.
How severe is CVE-2018-13983?
CVE-2018-13983 has a severity rating of 6.1, which is considered medium.
How does CVE-2018-13983 occur?
CVE-2018-13983 occurs due to improper validation of user-supplied input in certain pages of ImpressCMS.
What is the impact of CVE-2018-13983?
The impact of CVE-2018-13983 is that it allows attackers to execute malicious code or steal sensitive information from users.
How can I mitigate CVE-2018-13983?
To mitigate CVE-2018-13983, it is recommended to update to a patched version of ImpressCMS.