CVE-2018-16624: XSS
Published May 13, 2019
·Updated
panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page.
Affected Software
1 affected component
getkirby Kirby=2.5.12
Event History
May 13, 2019
CVE Published
via MITRE·12:56 PM
Data Sourced
via MITRE·12:56 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16624?
CVE-2018-16624 is classified as a medium severity vulnerability due to its potential to allow cross-site scripting (XSS) attacks.
2
How do I fix CVE-2018-16624?
To mitigate CVE-2018-16624, update your Kirby installation to the latest version that addresses this XSS vulnerability.
3
What type of vulnerability is CVE-2018-16624?
CVE-2018-16624 is a cross-site scripting (XSS) vulnerability affecting the title input functionality in Kirby v2.5.12.
4
What software is affected by CVE-2018-16624?
CVE-2018-16624 specifically affects Kirby version 2.5.12.
5
Can CVE-2018-16624 lead to data breaches?
Yes, CVE-2018-16624 can potentially lead to data breaches through malicious scripts executed in users' browsers.