First published: Thu Dec 27 2018(Updated: )
MiniCMS V1.10 has XSS via the mc-admin/post-edit.php query string, a related issue to CVE-2018-10296 and CVE-2018-16233.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
1234n Minicms | =1.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20520 is a vulnerability in MiniCMS V1.10 that allows for cross-site scripting (XSS) attacks via the mc-admin/post-edit.php query string.
CVE-2018-20520 has a medium severity rating of 6.1 (out of 10).
CVE-2018-20520 allows attackers to exploit a vulnerability in MiniCMS V1.10 and perform cross-site scripting (XSS) attacks.
To fix CVE-2018-20520, it is recommended to update MiniCMS to a version that addresses the vulnerability or apply any available patches or security fixes provided by the vendor.
More information about CVE-2018-20520 can be found at the following reference: [https://github.com/bg5sbk/MiniCMS/issues/27](https://github.com/bg5sbk/MiniCMS/issues/27)