CVE-2018-14973: XSS
Published Aug 6, 2018
·Updated
An issue was discovered in QCMS 3.0.1. upload/System/Controller/backend/product.php has XSS.
Affected Software
1 affected component
Q-cms Qcms=3.0.1
Event History
Aug 6, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
Which component and version are identified as affected?
The affected component is identified as upload/System/Controller/backend/product.php in QCMS 3.0.1. The provided data does not identify other affected versions.
2
What access and conditions are required for exploitation?
The CVSS vector indicates network reachability, low attack complexity, high privileges required, and user interaction required. An attacker would therefore need elevated privileges and a user to interact with the malicious content.
3
What is the stated security impact?
The issue can affect confidentiality and integrity across a changed security scope, while availability impact is listed as none. The provided CVSS score is 4.8 (medium).