First published: Sun Oct 28 2018(Updated: )
An XSS issue was discovered in SEMCMS 3.4 via the first input field to the admin/SEMCMS_Link.php?lgid=1 URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
sem-cms | =3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18740 is an XSS (cross-site scripting) vulnerability in SEMCMS version 3.4.
This vulnerability can be exploited by an attacker by injecting malicious code into the first input field of the admin/SEMCMS_Link.php?lgid=1 URI.
The severity of CVE-2018-18740 is medium with a CVSS score of 4.8.
To fix this vulnerability, it is recommended to upgrade SEMCMS to a version higher than 3.4.
More information about CVE-2018-18740 can be found at the following link: [XSS.md](https://github.com/AvaterXXX/SEMCMS/blob/master/XSS.md#xss4).