First published: Mon May 13 2019(Updated: )
Kirby V2.5.12 is prone to a Persistent XSS attack via the Title of the "Site options" in the admin panel dashboard dropdown.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Getkirby Kirby | =2.5.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16623 is a vulnerability in Kirby V2.5.12 that allows for a Persistent XSS attack via the Title of the Site options in the admin panel dashboard dropdown.
CVE-2018-16623 has a severity rating of medium with a score of 4.8.
Kirby V2.5.12 is affected by CVE-2018-16623.
To fix CVE-2018-16623, it is recommended to update Kirby to a version that includes a fix for this vulnerability.
CVE-2018-16623 is associated with the CWE ID 79.