CVE-2018-15199: XSS
Published Aug 8, 2018
·Updated
AuraCMS 2.3 allows XSS via a Bukutamu -> AddGuestbook action.
Affected Software
1 affected component
AuraCMS AuraCMS=2.3
Event History
Aug 8, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-15199?
CVE-2018-15199 has a medium severity rating due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2018-15199?
To fix CVE-2018-15199, you should update AuraCMS to the latest version that addresses this vulnerability.
3
What are the exploitation scenarios for CVE-2018-15199?
Exploitation of CVE-2018-15199 can occur if an attacker convinces a user to interact with a malicious guestbook entry.
4
Are all versions of AuraCMS affected by CVE-2018-15199?
Only AuraCMS version 2.3 is specifically noted to be affected by CVE-2018-15199.
5
What type of vulnerability is CVE-2018-15199?
CVE-2018-15199 is classified as a Cross-Site Scripting (XSS) vulnerability.