CVE-2018-5331: XSS
Discuz! DiscuzX X3.4 has XSS via the view parameter to include/space/spacepoll.php, as demonstrated by a mod=space do=poll request to home.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-5331?
CVE-2018-5331 is classified as a medium severity vulnerability due to its potential for exploiting XSS attacks.
How do I fix CVE-2018-5331?
To fix CVE-2018-5331, you should update to a patched version of Discuz! that addresses the XSS issue.
What systems are affected by CVE-2018-5331?
CVE-2018-5331 affects the DiscuzX version X3.4, which is susceptible to XSS through specific input parameters.
What kind of attack can CVE-2018-5331 facilitate?
CVE-2018-5331 can facilitate cross-site scripting (XSS) attacks, allowing attackers to execute arbitrary scripts in the user's browser.
How can I determine if my application is vulnerable to CVE-2018-5331?
You can determine if your application is vulnerable to CVE-2018-5331 by checking if it runs DiscuzX version X3.4 and testing for XSS via the specified parameters.