CVE-2018-20418: XSS
Published Dec 24, 2018
·Updated
index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.
Other sources
index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.
Affected Software
2 affected components
composer/craftcms/cms<=3.0.25
Craft CMS=3.0.25
Event History
Dec 24, 2018
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
May 14, 2022
Advisory Published
via GitHub·01:20 AM
Frequently Asked Questions
1
What is CVE-2018-20418?
CVE-2018-20418 is a vulnerability in Craft CMS 3.0.25 that allows for cross-site scripting (XSS) attacks.
2
How severe is CVE-2018-20418?
CVE-2018-20418 has a severity rating of 4.8 out of 10, which is considered medium.
3
How does CVE-2018-20418 allow for XSS attacks?
CVE-2018-20418 allows XSS attacks by allowing an attacker to save a new title from the console tab.
4
What is the affected software of CVE-2018-20418?
The affected software is Craft CMS 3.0.25.
5
How can I fix CVE-2018-20418?
To fix CVE-2018-20418, upgrade to a version of Craft CMS that is not affected by this vulnerability.