CVE-2018-19170: XSS
Published Nov 11, 2018
·Updated
In JPress v1.0-rc.5, there is stored XSS via each of the first three input fields to the starter-tomcat-1.0/admin/setting URI, as demonstrated by the webname parameter.
Affected Software
1 affected component
jpress Jpress=1.0-rc5
Event History
Nov 11, 2018
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19170?
CVE-2018-19170 has a medium severity rating due to its potential for stored XSS attacks.
2
How do I fix CVE-2018-19170?
To fix CVE-2018-19170, sanitize all input fields in the starter-tomcat-1.0/admin/setting URI to prevent stored XSS.
3
What versions of JPress are affected by CVE-2018-19170?
CVE-2018-19170 affects JPress version 1.0-rc.5.
4
What type of vulnerability is CVE-2018-19170?
CVE-2018-19170 is a stored cross-site scripting (XSS) vulnerability.
5
Where in JPress can CVE-2018-19170 be exploited?
CVE-2018-19170 can be exploited through the first three input fields to the starter-tomcat-1.0/admin/setting URI.