CVE-2018-19461: XSS
Published Jun 7, 2019
·Updated
admin\db\DoSql.php in EmpireCMS through 7.5 allows XSS via crafted SQL syntax to admin/admin.php.
Affected Software
1 affected component
Phome Empirecms<=7.5.0
Event History
Jun 7, 2019
CVE Published
via MITRE·04:46 PM
Data Sourced
via MITRE·04:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19461?
CVE-2018-19461 is considered a medium severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2018-19461?
To fix CVE-2018-19461, upgrade EmpireCMS to version 7.5.1 or later, which addresses the vulnerability.
3
Who is affected by CVE-2018-19461?
Users of EmpireCMS versions up to and including 7.5 are vulnerable to CVE-2018-19461.
4
What types of attacks can CVE-2018-19461 facilitate?
CVE-2018-19461 can facilitate Cross-Site Scripting (XSS) attacks that could compromise user sessions or data integrity.
5
What are the implications of CVE-2018-19461 for website security?
CVE-2018-19461 poses a risk to website security by allowing attackers to inject malicious scripts into web pages viewed by users.