CVE-2018-15563: XSS
Published Oct 2, 2018
·Updated
core/admin/pages/add/ in Subrion CMS 4.2.1 has XSS via the titles[en] parameter.
Other sources
core/admin/pages/add/ in Subrion CMS 4.2.1 has XSS via the titles[en] parameter.
— GitHub
Affected Software
2 affected components
composer/intelliants/subrion<=4.2.1
Intelliants Subrion=4.2.1
Event History
Oct 2, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·02:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-15563.
2
What is the severity of CVE-2018-15563?
The severity of CVE-2018-15563 is medium.
3
How can the vulnerability be exploited?
The vulnerability can be exploited via the titles[en] parameter in _core/admin/pages/add/ in Subrion CMS 4.2.1, allowing for XSS attacks.
4
What software versions are affected by this vulnerability?
The vulnerability affects Subrion CMS 4.2.1.
5
Is there a fix available for CVE-2018-15563?
Yes, it is recommended to update to a patched version of Subrion CMS to fix CVE-2018-15563.