CVE-2018-19464: XSS
Discuz! X3.4 allows XSS via admin.php because admincp/admincpsetting.php and template\default\common\footer.htm mishandles statcode field from third-party stats code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19464?
The severity of CVE-2018-19464 is classified as medium due to its potential for XSS attacks affecting the admin interface.
How do I fix CVE-2018-19464?
To fix CVE-2018-19464, update to a patched version of Discuz! that addresses the XSS vulnerability in admin.php.
What types of attacks can CVE-2018-19464 facilitate?
CVE-2018-19464 can facilitate cross-site scripting (XSS) attacks, allowing an attacker to inject malicious scripts into the admin interface.
Which versions of Discuz! are affected by CVE-2018-19464?
CVE-2018-19464 affects Discuz! version 3.4 specifically.
What are the consequences of an exploit of CVE-2018-19464?
Exploiting CVE-2018-19464 could allow an attacker to execute arbitrary code within the browser session of an admin user, potentially compromising the site.