First published: Fri Sep 14 2018(Updated: )
MiniCMS 1.10, when Internet Explorer is used, allows XSS via a crafted URI because $_SERVER['REQUEST_URI'] is mishandled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
1234n Minicms | =1.10 | |
Microsoft Internet Explorer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17039 is a vulnerability in MiniCMS 1.10 that allows XSS (Cross-Site Scripting) attacks when Internet Explorer is used.
CVE-2018-17039 allows an attacker to execute arbitrary scripts on vulnerable versions of MiniCMS 1.10 when accessed using Internet Explorer.
The XSS attack is possible in CVE-2018-17039 due to mishandling of the $_SERVER['REQUEST_URI'] variable in MiniCMS 1.10 when accessed using Internet Explorer.
CVE-2018-17039 has a severity level classified as medium with a CVSS score of 6.1.
No, Internet Explorer itself is not vulnerable to CVE-2018-17039, it is the combination of Internet Explorer and MiniCMS 1.10 that allows the XSS attack.