First published: Sun Sep 02 2018(Updated: )
SeaCMS V6.61 has XSS via the admin_video.php v_content parameter, related to the site name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Seacms Seacms | =6.61 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16348 is a vulnerability in SeaCMS V6.61 that allows cross-site scripting (XSS) attacks via the admin_video.php v_content parameter related to the site name.
CVE-2018-16348 has a severity rating of 4.8, which is considered medium.
CVE-2018-16348 affects SeaCMS V6.61 specifically, allowing XSS attacks through the admin_video.php v_content parameter related to the site name.
CVE-2018-16348 is associated with CWE-79, which is the weakness category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
To fix CVE-2018-16348, it is recommended to update to a patched version of SeaCMS V6.61 that addresses the XSS vulnerability.