CVE-2018-20212: XSS
bin/statistics in TWiki 6.0.2 allows cross-site scripting (XSS) via the webs parameter.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-20212.
What is the title of the vulnerability?
The title of the vulnerability is bin/statistics in TWiki 6.0.2 allows cross-site scripting (XSS) via the webs parameter.
What is the severity of CVE-2018-20212?
The severity of CVE-2018-20212 is medium.
How is TWiki 6.0.2 affected by CVE-2018-20212?
TWiki 6.0.2 is affected by CVE-2018-20212 due to the cross-site scripting (XSS) vulnerability in the bin/statistics module.
How can the cross-site scripting (XSS) vulnerability in TWiki 6.0.2 be exploited?
The cross-site scripting (XSS) vulnerability in TWiki 6.0.2 can be exploited via the webs parameter in the bin/statistics module.
Are there any known references for CVE-2018-20212?
Yes, there are references available for CVE-2018-20212. You can find them at the following links: [1] http://packetstormsecurity.com/files/151028/TWiki-6.0.2-Cross-Site-Scripting.html, [2] http://seclists.org/fulldisclosure/2019/Jan/7, [3] http://twiki.org/cgi-bin/view/Codev/DownloadTWiki
What is the Common Weakness Enumeration (CWE) ID associated with CVE-2018-20212?
The Common Weakness Enumeration (CWE) ID associated with CVE-2018-20212 is CWE-79, which represents Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').