CVE-2018-19465: XSS
Published Jun 7, 2019
·Updated
Maccms through 8.0 allows XSS via the sitekeywords field to index.php?m=system-config because of tpl/module/system.php and tpl/html/systemconfig.html, related to template/paody/html/vodindex.html.
Affected Software
1 affected component
maccms Maccms<=8.0
Event History
Jun 7, 2019
CVE Published
via MITRE·04:40 PM
Data Sourced
via MITRE·04:40 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-19465.
2
What is the severity of CVE-2018-19465?
The severity of CVE-2018-19465 is medium with a severity value of 6.1.
3
How does Maccms through 8.0 allow XSS?
Maccms through 8.0 allows XSS via the site_keywords field to index.php?m=system-config.
4
What software is affected by CVE-2018-19465?
The Maccms software version 8.0 is affected by CVE-2018-19465.
5
How can I fix CVE-2018-19465?
To fix CVE-2018-19465, update Maccms to a version higher than 8.0 and apply any recommended patches or fixes.