CVE-2018-17321: XSS
Published Sep 22, 2018
·Updated
An issue was discovered in SeaCMS 6.64. XSS exists in admindatarelate.php via the time or maxHit parameter in a dorandomset action.
Affected Software
1 affected component
SEACMS SEACMS=6.64
Event History
Sep 22, 2018
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is CVE-2018-17321?
CVE-2018-17321 is a vulnerability in SeaCMS 6.64 that allows for cross-site scripting (XSS) attacks.
2
How severe is CVE-2018-17321?
CVE-2018-17321 has a severity score of 6.1, which is considered medium severity.
3
How does CVE-2018-17321 occur?
CVE-2018-17321 occurs in the admin_datarelate.php file of SeaCMS 6.64 when the time or maxHit parameter is used in a dorandomset action.
4
What is the impact of CVE-2018-17321?
The impact of CVE-2018-17321 is that it allows an attacker to execute arbitrary JavaScript code in the victim's browser, potentially leading to information theft or malicious actions.
5
Is there a fix for CVE-2018-17321?
Yes, to fix CVE-2018-17321, update to a version of SeaCMS that is not affected by this vulnerability.