CVE-2018-20136: XSS
Published Dec 13, 2018
·Updated
XSS exists in FUEL CMS 1.4.3 via the Header or Body in the Layout Variables during new-page creation, as demonstrated by the pages/edit/1?lang=english URI.
Affected Software
1 affected component
TheDayLightStudio Fuel CMS=1.4.3
Event History
Dec 13, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-20136?
CVE-2018-20136 is a vulnerability in FUEL CMS 1.4.3 that allows for XSS attacks through the Header or Body in the Layout Variables during new-page creation.
2
How severe is CVE-2018-20136?
CVE-2018-20136 has a severity rating of medium, with a severity value of 4.8.
3
How does CVE-2018-20136 affect FUEL CMS?
CVE-2018-20136 affects FUEL CMS 1.4.3.
4
How can CVE-2018-20136 be exploited?
CVE-2018-20136 can be exploited by crafting malicious payloads in the Header or Body of the Layout Variables during new-page creation in FUEL CMS.
5
Is there a fix for CVE-2018-20136?
At this time, there is no known fix for CVE-2018-20136. It is recommended to update to the latest version of FUEL CMS when a fix becomes available.