First published: Fri Sep 07 2018(Updated: )
Gxlcms 1.0 has XSS via the PATH_INFO to gx/lib/ThinkPHP/Tpl/ThinkException.tpl.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Usualtool CMS | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-16655.
The severity of CVE-2018-16655 is medium, with a severity value of 6.1.
The vulnerability CVE-2018-16655 affects Gxlcms 1.0 by allowing XSS (cross-site scripting) attacks via the PATH_INFO to gx/lib/ThinkPHP/Tpl/ThinkException.tpl.php.
Unfortunately, there is no information available about a fix for CVE-2018-16655.
Yes, there are references available for CVE-2018-16655. You can find them at the following links: [https://github.com/lengjibo/lengjibo.github.io/blob/master/gxlcms/index.html](https://github.com/lengjibo/lengjibo.github.io/blob/master/gxlcms/index.html) and [https://lengjibo.github.io/gxlcms/](https://lengjibo.github.io/gxlcms/)