CVE-2018-16350: XSS
Published Sep 2, 2018
·Updated
WUZHI CMS 4.1.0 has XSS via the index.php?m=core&f=set&v=basic form[statcode] parameter.
Affected Software
1 affected component
Wuzhi Cms Project Wuzhi Cms=4.1.0
Event History
Sep 2, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16350?
CVE-2018-16350 has a medium severity rating due to its potential for Cross-Site Scripting (XSS) attacks that can compromise user data.
2
How do I fix CVE-2018-16350?
To fix CVE-2018-16350, you should validate and sanitize user input, especially the form[statcode] parameter in the WUZHI CMS 4.1.0 application.
3
What kind of attack does CVE-2018-16350 allow?
CVE-2018-16350 allows attackers to perform Cross-Site Scripting (XSS) attacks by exploiting the vulnerable input parameter in WUZHI CMS.
4
Is CVE-2018-16350 specific to certain versions of WUZHI CMS?
Yes, CVE-2018-16350 specifically affects WUZHI CMS version 4.1.0.
5
What is the impact of CVE-2018-16350 on user data?
CVE-2018-16350 can lead to unauthorized access to user sessions, data theft, and the potential spread of malicious scripts.