First published: Fri Sep 28 2018(Updated: )
An issue was discovered in YMFE YApi 1.3.23. There is stored XSS in the name field of a project.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
YAPIG | =1.3.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-17574 is classified as a medium severity vulnerability due to the potential for stored cross-site scripting (XSS) attacks.
To mitigate CVE-2018-17574, ensure that input sanitization is implemented for the name field of projects in YApi 1.3.22.
CVE-2018-17574 is a stored cross-site scripting (XSS) vulnerability affecting YApi version 1.3.22.
CVE-2018-17574 affects YApi version 1.3.22 and may also impact earlier versions.
As of now, there is no specific patch released for CVE-2018-17574; upgrading to a secured version is recommended.