CVE-2018-20137: XSS
XSS exists in FUEL CMS 1.4.3 via the Page title, Meta description, or Meta keywords during page data management, as demonstrated by the pages/edit/1?lang=english URI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20137?
The severity of CVE-2018-20137 is medium with a severity score of 4.8.
How does XSS occur in FUEL CMS 1.4.3?
XSS occurs in FUEL CMS 1.4.3 through the Page title, Meta description, or Meta keywords during page data management.
How can I fix the XSS vulnerability in FUEL CMS 1.4.3?
To fix the XSS vulnerability in FUEL CMS 1.4.3, update to a version that has addressed the vulnerability and sanitize user input in the Page title, Meta description, and Meta keywords fields.
Where can I find more information about the CVE-2018-20137 vulnerability?
You can find more information about the CVE-2018-20137 vulnerability at the following reference link: https://github.com/CCCCCrash/POCs/tree/master/Web/fuel-cms/xss1.
What is the CWE for CVE-2018-20137?
The CWE for CVE-2018-20137 is CWE-79, which is Cross-Site Scripting (XSS).