CVE-2018-19902: XSS
Published Dec 31, 2018
·Updated
No-CMS 1.1.3 is prone to Persistent XSS via the blog/managearticle "keyword" parameter.
Affected Software
1 affected component
No-cms Project No-cms=1.1.3
Event History
Dec 31, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19902?
CVE-2018-19902 is considered a high severity vulnerability due to its potential for exploitation through persistent XSS.
2
How do I fix CVE-2018-19902?
To fix CVE-2018-19902, update to a version of No-CMS that addresses the persistent XSS vulnerability.
3
What systems are affected by CVE-2018-19902?
CVE-2018-19902 specifically affects No-CMS version 1.1.3.
4
What is Persistent XSS in the context of CVE-2018-19902?
Persistent XSS in CVE-2018-19902 refers to an attack where malicious scripts are injected through the 'keyword' parameter and stored for future execution.
5
Are there any known exploits for CVE-2018-19902?
At the moment, there are no public disclosures of active exploits for CVE-2018-19902, but the risk remains due to its nature.