CVE-2018-18738: XSS
Published Oct 28, 2018
·Updated
An XSS issue was discovered in SEMCMS 3.4 via the admin/SEMCMSCategories.php?pid=1&lgid=1 categorykey parameter.
Affected Software
1 affected component
Sem-cms Semcms=3.4
Event History
Oct 28, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this XSS issue?
The vulnerability ID for this XSS issue is CVE-2018-18738.
2
What is the affected software for this vulnerability?
The affected software is SEMCMS version 3.4.
3
How severe is this vulnerability?
This vulnerability has a severity level of medium (4.8).
4
How can I exploit this XSS issue in SEMCMS 3.4?
To exploit this XSS issue, you can manipulate the category_key parameter in the admin/SEMCMS_Categories.php?pid=1&lgid=1 page.
5
Where can I find more information about this vulnerability?
You can find more information about this vulnerability [here](https://github.com/AvaterXXX/SEMCMS/blob/master/XSS.md#xss2).