CVE-2018-19092: XSS
Published Nov 7, 2018
·Updated
An issue was discovered in YzmCMS v5.2. It has XSS via a search/index/archives/pubtime/ query string, as demonstrated by the search/index/archives/pubtime/1526387722/page/1.html URI. NOTE: this does not obtain a user's cookie.
Affected Software
1 affected component
YzmCMS YzmCMS=5.2
Event History
Nov 7, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19092?
The severity of CVE-2018-19092 is considered medium due to its XSS vulnerability.
2
How do I fix CVE-2018-19092?
To fix CVE-2018-19092, update YzmCMS to a patched version that addresses the XSS vulnerability.
3
What type of vulnerability is CVE-2018-19092?
CVE-2018-19092 is a cross-site scripting (XSS) vulnerability affecting YzmCMS v5.2.
4
What versions of YzmCMS are affected by CVE-2018-19092?
CVE-2018-19092 affects YzmCMS version 5.2 specifically.
5
Can CVE-2018-19092 be exploited to steal user cookies?
No, CVE-2018-19092 does not obtain a user's cookie despite being an XSS vulnerability.