CVE-2018-18938: XSS
An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via an ontoggle attribute to details/open/ within a second input field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18938?
The severity of CVE-2018-18938 is medium with a severity value of 4.8.
What is the affected software version of CVE-2018-18938?
CVE-2018-18938 affects WUZHI CMS version 4.1.0.
How can I exploit the vulnerability in CVE-2018-18938?
To exploit the vulnerability in CVE-2018-18938, an attacker can inject malicious code into the ontoggle attribute of the details/open/ within a second input field in the index.php?m=core&f=index page.
Are there any known fixes for CVE-2018-18938?
At the moment, there are no known fixes for CVE-2018-18938. It is recommended to update to a newer version of WUZHI CMS or apply any patches or mitigations provided by the vendor, if available.
Where can I find more information about CVE-2018-18938?
More information about CVE-2018-18938 can be found at the following link: [https://github.com/wuzhicms/wuzhicms/issues/158](https://github.com/wuzhicms/wuzhicms/issues/158)