CVE-2018-18740: XSS
Published Oct 28, 2018
·Updated
An XSS issue was discovered in SEMCMS 3.4 via the first input field to the admin/SEMCMSLink.php?lgid=1 URI.
Affected Software
1 affected component
Sem-cms Semcms=3.4
Event History
Oct 28, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is CVE-2018-18740?
CVE-2018-18740 is an XSS (cross-site scripting) vulnerability in SEMCMS version 3.4.
2
How can this vulnerability be exploited?
This vulnerability can be exploited by an attacker by injecting malicious code into the first input field of the admin/SEMCMS_Link.php?lgid=1 URI.
3
What is the severity of CVE-2018-18740?
The severity of CVE-2018-18740 is medium with a CVSS score of 4.8.
4
How can I fix this vulnerability?
To fix this vulnerability, it is recommended to upgrade SEMCMS to a version higher than 3.4.
5
Where can I find more information about this vulnerability?
More information about CVE-2018-18740 can be found at the following link: [XSS.md](https://github.com/AvaterXXX/SEMCMS/blob/master/XSS.md#xss4).