First published: Fri Nov 09 2018(Updated: )
An issue was discovered in S-CMS v1.5. There is an XSS vulnerability in search.php via the keyword parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
S-cms S-cms | =1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the XSS vulnerability in S-CMS v1.5 is CVE-2018-19145.
The severity level of CVE-2018-19145 is medium with a CVSSv3 score of 6.1.
The XSS vulnerability in S-CMS v1.5 occurs in the search.php file via the keyword parameter.
Only version 1.5 of S-CMS is affected by CVE-2018-19145.
Yes, a proof-of-concept for the XSS vulnerability in S-CMS is available at the following link: https://kingflyme.blogspot.com/2018/11/the-poc-of-s-cmsxss.html.