CVE-2018-16623: XSS
Published May 13, 2019
·Updated
Kirby V2.5.12 is prone to a Persistent XSS attack via the Title of the "Site options" in the admin panel dashboard dropdown.
Affected Software
1 affected component
getkirby Kirby=2.5.12
Event History
May 13, 2019
CVE Published
via MITRE·12:57 PM
Data Sourced
via MITRE·12:57 PM
Description
Frequently Asked Questions
1
What is CVE-2018-16623?
CVE-2018-16623 is a vulnerability in Kirby V2.5.12 that allows for a Persistent XSS attack via the Title of the Site options in the admin panel dashboard dropdown.
2
How severe is CVE-2018-16623?
CVE-2018-16623 has a severity rating of medium with a score of 4.8.
3
What software is affected by CVE-2018-16623?
Kirby V2.5.12 is affected by CVE-2018-16623.
4
How can I fix CVE-2018-16623?
To fix CVE-2018-16623, it is recommended to update Kirby to a version that includes a fix for this vulnerability.
5
What is the CWE ID for CVE-2018-16623?
CVE-2018-16623 is associated with the CWE ID 79.