CVE-2018-17425: XSS
Published Mar 7, 2019
·Updated
WUZHI CMS 4.1.0 has stored XSS via the "Membership Center" "I want to ask" "detailed description" field under the index.php?m=member URI.
Affected Software
2 affected components
Wuzhicms Wuzhi Cms=4.1.0
Wuzhicms Wuzhicms=4.1.0
Event History
Mar 7, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·11:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-17425.
2
What is the severity of CVE-2018-17425?
The severity of CVE-2018-17425 is medium with a CVSS score of 5.4.
3
What software is affected by CVE-2018-17425?
WUZHI CMS version 4.1.0 is affected by CVE-2018-17425.
4
How does the vulnerability manifest?
The vulnerability manifests as stored XSS through the "detailed description" field under the index.php?m=member URI in the "Membership Center" of WUZHI CMS version 4.1.0.
5
Is there a fix for CVE-2018-17425?
Currently, there is no official fix available for CVE-2018-17425. It is recommended to follow the provided reference link for any updates or patches.