CVE-2018-17300: XSS
Published Sep 21, 2018
·Updated
Stored XSS exists in CuppaCMS through 2018-09-03 via an administrator/#/component/tablemanager/view/cumenus section name.
Affected Software
1 affected component
CuppaCMS CuppaCMS<2018-09-04
Event History
Sep 21, 2018
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-17300?
CVE-2018-17300 is classified as a medium-severity stored XSS vulnerability.
2
How do I fix CVE-2018-17300?
To fix CVE-2018-17300, upgrade CuppaCMS to version 2018-09-04 or later.
3
Who is affected by CVE-2018-17300?
CVE-2018-17300 affects users of CuppaCMS versions prior to 2018-09-04.
4
What kind of attacks can CVE-2018-17300 lead to?
CVE-2018-17300 can lead to attacks such as session hijacking, data theft, or defacement due to stored XSS.
5
Is there any workaround for CVE-2018-17300?
There are no known workarounds for CVE-2018-17300 other than applying the recommended upgrade.