CVE-2018-17426: XSS
Published Mar 7, 2019
·Updated
WUZHI CMS 4.1.0 has stored XSS via the "Extension module" "SMS in station" field under the index.php?m=core URI.
Affected Software
2 affected components
Wuzhicms Wuzhi Cms=4.1.0
Wuzhicms Wuzhicms=4.1.0
Event History
Mar 7, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·11:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2018-17426?
CVE-2018-17426 is a vulnerability in WUZHI CMS 4.1.0 that allows for stored cross-site scripting (XSS) attacks.
2
How does the vulnerability occur?
The vulnerability occurs when an attacker injects malicious code into the 'SMS in station' field under 'Extension module' in the index.php?m=core URI.
3
What is the severity of CVE-2018-17426?
The severity of CVE-2018-17426 is medium with a severity value of 5.4.
4
How can I fix CVE-2018-17426?
To fix CVE-2018-17426, update WUZHI CMS to a version that is not affected by the vulnerability.
5
Is there any reference to CVE-2018-17426?
Yes, you can find more information about CVE-2018-17426 at the following link: https://github.com/wuzhicms/wuzhicms/issues/154