First published: Thu Jan 25 2018(Updated: )
Cross-site scripting (XSS) in WBCE CMS 1.3.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the Modify Page screen, a different issue than CVE-2017-2118.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Wbce CMS | =1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-6313.
The affected software is WBCE CMS version 1.3.1.
The severity of CVE-2018-6313 is medium with a severity value of 4.8.
CVE-2018-6313 allows remote authenticated administrators to inject arbitrary web script or HTML via the Modify Page screen.
To fix the XSS vulnerability in WBCE CMS 1.3.1, it is recommended to apply the latest security patch or upgrade to a newer version that addresses the issue.