CVE-2018-18927: XSS
Published Nov 4, 2018
·Updated
An issue was discovered in PublicCMS V4.0. It allows XSS by modifying the pagelist "attached" attribute (which typically has 'class="icon-globe icon-large"' in its value), as demonstrated by an 'UPDATE sysmodule SET attached = "[XSS]" WHERE id="pagelist"' statement.
Affected Software
1 affected component
PublicCMS publiccms=4.0
Event History
Nov 4, 2018
CVE Published
05:29 AM
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-18927.
2
What is the severity of CVE-2018-18927?
The severity of CVE-2018-18927 is medium with a severity value of 4.8.
3
What is the affected software?
The affected software is PublicCMS version 4.0.
4
What is the CWE (Common Weakness Enumeration) ID for this vulnerability?
The CWE ID for this vulnerability is CWE-79.
5
How can I fix CVE-2018-18927?
To fix CVE-2018-18927, apply the appropriate patch or upgrade to a fixed version of PublicCMS.