CVE-2018-16805: XSS
Published Sep 10, 2018
·Updated
In b3log Solo 2.9.3, XSS in the Input page under the Publish Articles menu, with an ID of linkAddress stored in the link JSON field, allows remote attackers to inject arbitrary Web scripts or HTML via a crafted site name provided by an administrator.
Affected Software
1 affected component
b3log Solo=2.9.3
Event History
Sep 10, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-16805?
CVE-2018-16805 has a medium severity due to its potential for cross-site scripting (XSS) vulnerabilities.
2
How do I fix CVE-2018-16805?
To fix CVE-2018-16805, you should update b3log Solo to the latest version that addresses this vulnerability.
3
What type of attack does CVE-2018-16805 enable?
CVE-2018-16805 enables attackers to perform cross-site scripting (XSS) attacks by injecting arbitrary web scripts.
4
Who is affected by CVE-2018-16805?
Users of b3log Solo version 2.9.3 are affected by CVE-2018-16805.
5
What component of b3log Solo is vulnerable in CVE-2018-16805?
The Input page under the Publish Articles menu is the vulnerable component in CVE-2018-16805.