CVE-2018-18868: XSS
Published Oct 31, 2018
·Updated
No-CMS 1.1.3 is prone to Persistent XSS via a contactus name parameter, as demonstrated by the VG48Z5PqVWname parameter.
Affected Software
1 affected component
No-cms Project No-cms=1.1.3
Event History
Oct 31, 2018
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18868?
CVE-2018-18868 is classified as a medium severity vulnerability due to its potential for persistent XSS attacks.
2
How do I fix CVE-2018-18868?
To fix CVE-2018-18868, sanitize and validate inputs for the contact_us name parameter to prevent XSS payloads.
3
What software version is affected by CVE-2018-18868?
CVE-2018-18868 affects No-CMS version 1.1.3.
4
What type of vulnerability is CVE-2018-18868?
CVE-2018-18868 is a Persistent Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2018-18868 be exploited remotely?
Yes, CVE-2018-18868 can be exploited remotely through crafted requests to the vulnerable application.