First published: Sun Mar 17 2019(Updated: )
bin/statistics in TWiki 6.0.2 allows cross-site scripting (XSS) via the webs parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Twiki Twiki | =6.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-20212.
The title of the vulnerability is bin/statistics in TWiki 6.0.2 allows cross-site scripting (XSS) via the webs parameter.
The severity of CVE-2018-20212 is medium.
TWiki 6.0.2 is affected by CVE-2018-20212 due to the cross-site scripting (XSS) vulnerability in the bin/statistics module.
The cross-site scripting (XSS) vulnerability in TWiki 6.0.2 can be exploited via the webs parameter in the bin/statistics module.
Yes, there are references available for CVE-2018-20212. You can find them at the following links: [1] http://packetstormsecurity.com/files/151028/TWiki-6.0.2-Cross-Site-Scripting.html, [2] http://seclists.org/fulldisclosure/2019/Jan/7, [3] http://twiki.org/cgi-bin/view/Codev/DownloadTWiki
The Common Weakness Enumeration (CWE) ID associated with CVE-2018-20212 is CWE-79, which represents Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').