CVE-2018-18381: XSS
Published Oct 16, 2018
·Updated
Z-BlogPHP 1.5.2.1935 (Zero) has a stored XSS Vulnerability in zbsystem/function/csystemadmin.php via the Content-Type header during the uploading of image attachments.
Affected Software
1 affected component
ZblogCN Z-blogphp=1.5.2.1935
Event History
Oct 16, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for Z-BlogPHP?
The vulnerability ID for Z-BlogPHP is CVE-2018-18381.
2
What is the severity of CVE-2018-18381?
CVE-2018-18381 has a severity rating of medium with a CVSS score of 5.4.
3
How does the stored XSS vulnerability in Z-BlogPHP occur?
The stored XSS vulnerability in Z-BlogPHP occurs in the zb_system/function/c_system_admin.php file when uploading image attachments using the Content-Type header.
4
What is the affected version of Z-BlogPHP for CVE-2018-18381?
The affected version of Z-BlogPHP for CVE-2018-18381 is 1.5.2.1935 (Zero).
5
Is there a fix available for CVE-2018-18381?
There is no specific fix available for CVE-2018-18381, but it is recommended to update to a newer version of Z-BlogPHP to address this vulnerability.