CVE-2018-18783: XSS
Published Oct 29, 2018
·Updated
XSS was discovered in SEMCMS V3.4 via the semcmsremail.php?type=ok umail parameter.
Affected Software
1 affected component
Sem-cms Semcms=3.4
Event History
Oct 29, 2018
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18783?
The severity of CVE-2018-18783 is medium (6.1).
2
How was the XSS vulnerability discovered in SEMCMS V3.4?
The XSS vulnerability was discovered in SEMCMS V3.4 via the semcms_remail.php?type=ok umail parameter.
3
What is the affected software version?
The affected software version is SEMCMS V3.4.
4
What is the CWE ID associated with this vulnerability?
The CWE ID associated with this vulnerability is CWE-79.
5
Where can I find more information about CVE-2018-18783?
You can find more information about CVE-2018-18783 at the following references: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/152197) and [Reference 2](https://github.com/m3lon/2018_Recorder/blob/master/SEMCMS%20DOM%20Based%20XSS.md).