CVE-2018-16348: XSS
SeaCMS V6.61 has XSS via the adminvideo.php vcontent parameter, related to the site name.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-16348?
CVE-2018-16348 is a vulnerability in SeaCMS V6.61 that allows cross-site scripting (XSS) attacks via the admin_video.php v_content parameter related to the site name.
How severe is CVE-2018-16348?
CVE-2018-16348 has a severity rating of 4.8, which is considered medium.
How does CVE-2018-16348 affect SeaCMS?
CVE-2018-16348 affects SeaCMS V6.61 specifically, allowing XSS attacks through the admin_video.php v_content parameter related to the site name.
What is the Common Weakness Enumeration (CWE) associated with CVE-2018-16348?
CVE-2018-16348 is associated with CWE-79, which is the weakness category for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
How can I fix CVE-2018-16348?
To fix CVE-2018-16348, it is recommended to update to a patched version of SeaCMS V6.61 that addresses the XSS vulnerability.