CVE-2018-16247: XSS
Published Jun 20, 2019
·Updated
YzmCMS 5.1 has XSS via the admin/systemmanage/userconfigadd.html title parameter.
Affected Software
1 affected component
YzmCMS YzmCMS=5.1
Event History
Jun 20, 2019
CVE Published
via MITRE·03:48 PM
Data Sourced
via MITRE·03:48 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16247?
The severity of CVE-2018-16247 is classified as moderate due to its potential for cross-site scripting (XSS) exploitation.
2
How do I fix CVE-2018-16247?
To fix CVE-2018-16247, ensure that input validation and output encoding are properly implemented for the title parameter in the admin panel.
3
Which version of Yzmcms is affected by CVE-2018-16247?
Yzmcms version 5.1 is the only affected version for CVE-2018-16247.
4
What type of vulnerability is CVE-2018-16247?
CVE-2018-16247 is a cross-site scripting (XSS) vulnerability.
5
How can CVE-2018-16247 affect users?
Exploitation of CVE-2018-16247 could allow attackers to execute malicious scripts in the context of the user’s browser, potentially compromising user data.