First published: Sat Nov 17 2018(Updated: )
In SeaCMS v6.6.4, there is stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change, as demonstrated by a data: URL in an OBJECT element.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Seacms Seacms | =6.64 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19350 is a vulnerability found in SeaCMS v6.6.4 that allows for stored XSS via the member.php?action=chgpwdsubmit email parameter during a password change.
The stored XSS vulnerability in SeaCMS v6.6.4 occurs when a data: URL in an OBJECT element is used in the member.php?action=chgpwdsubmit email parameter during a password change process.
CVE-2018-19350 has a severity rating of medium with a CVSS score of 5.4.
To fix the stored XSS vulnerability in SeaCMS v6.6.4, it is recommended to apply the latest patch or upgrade to a newer version that addresses the vulnerability.
You can find more information about CVE-2018-19350, including a demonstration and details, in the following GitHub repository: https://github.com/Xmansec/seacms_vul/tree/master/XSS