CVE-2018-19901: XSS
Published Dec 31, 2018
·Updated
No-CMS 1.1.3 is prone to Persistent XSS via the blog/managearticle/index/ "articletitle" parameter.
Affected Software
1 affected component
No-cms Project No-cms=1.1.3
Event History
Dec 31, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19901?
CVE-2018-19901 has been classified as a high severity vulnerability due to its potential for persistent XSS attacks.
2
How do I fix CVE-2018-19901?
To fix CVE-2018-19901, you should sanitize and validate the 'article_title' parameter before processing user input.
3
What are the potential impacts of exploiting CVE-2018-19901?
Exploiting CVE-2018-19901 could allow attackers to inject malicious scripts that run in the context of the user's browser.
4
Is CVE-2018-19901 present in versions other than 1.1.3?
CVE-2018-19901 specifically affects No-CMS version 1.1.3 and may not be present in earlier or later versions.
5
Who is affected by CVE-2018-19901?
Anyone using No-CMS version 1.1.3 is affected by CVE-2018-19901 and should take action to protect their application.