First published: Sat Sep 22 2018(Updated: )
An issue was discovered in SeaCMS 6.64. XSS exists in admin_datarelate.php via the time or maxHit parameter in a dorandomset action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Seacms Seacms | =6.64 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17321 is a vulnerability in SeaCMS 6.64 that allows for cross-site scripting (XSS) attacks.
CVE-2018-17321 has a severity score of 6.1, which is considered medium severity.
CVE-2018-17321 occurs in the admin_datarelate.php file of SeaCMS 6.64 when the time or maxHit parameter is used in a dorandomset action.
The impact of CVE-2018-17321 is that it allows an attacker to execute arbitrary JavaScript code in the victim's browser, potentially leading to information theft or malicious actions.
Yes, to fix CVE-2018-17321, update to a version of SeaCMS that is not affected by this vulnerability.