CVE-2018-14520: XSS
Published Aug 24, 2022
·Updated
An issue was discovered in Kirby 2.5.12. The application allows malicious HTTP requests to be sent in order to trick a user into adding web pages.
Affected Software
1 affected component
getkirby Kirby=2.5.12
Event History
Aug 24, 2022
CVE Published
via MITRE·07:43 PM
Data Sourced
via MITRE·07:43 PM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-14520?
CVE-2018-14520 has a moderate severity rating due to its potential for Cross-Site Request Forgery (CSRF) attacks.
2
How do I fix CVE-2018-14520?
To fix CVE-2018-14520, upgrade to a newer version of Kirby that addresses this vulnerability.
3
What type of attacks can CVE-2018-14520 facilitate?
CVE-2018-14520 can facilitate Cross-Site Request Forgery (CSRF) attacks by tricking users into adding malicious web pages.
4
Which version of Kirby is affected by CVE-2018-14520?
CVE-2018-14520 affects Kirby version 2.5.12.
5
Who is impacted by CVE-2018-14520?
Users of Kirby 2.5.12 are primarily impacted by CVE-2018-14520 and should take necessary precautions.