CVE-2018-14512: XSS
An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[nickname] parameter to the index.php?m=core&f=set&v=sendmail URI. When the administrator accesses the "system settings - mail server" screen, the XSS payload is triggered.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14512?
The severity of CVE-2018-14512 is medium with a severity value of 6.1.
What is the affected software version of CVE-2018-14512?
CVE-2018-14512 affects WUZHI CMS version 4.1.0.
How does CVE-2018-14512 work?
CVE-2018-14512 is a persistent XSS vulnerability that allows remote attackers to inject arbitrary web script or HTML by exploiting the form[nickname] parameter in the index.php?m=core&f=set&v=sendmail URI.
Is there a fix available for CVE-2018-14512?
Currently, there is no known fix available for CVE-2018-14512. It is recommended to update to a newer version of WUZHI CMS or apply any patches or workarounds provided by the vendor.
Where can I find more information about CVE-2018-14512?
You can find more information about CVE-2018-14512 on the GitHub issue page: https://github.com/wuzhicms/wuzhicms/issues/143