CVE-2018-7198: XSS
October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/rainlab/blog-pluginto a version that resolves this vulnerability.Fixed in 1.4.1
Event History
Frequently Asked Questions
What is CVE-2018-7198?
CVE-2018-7198 is a vulnerability that allows XSS (Cross-Site Scripting) attacks in October CMS through version 1.0.431 by entering HTML on the Add Posts page.
How does CVE-2018-7198 affect October CMS?
CVE-2018-7198 affects October CMS through version 1.0.431 by allowing XSS attacks when HTML is entered on the Add Posts page.
What is the severity of CVE-2018-7198?
CVE-2018-7198 has a severity rating of medium (6.1) based on the CVSS (Common Vulnerability Scoring System).
How can I fix CVE-2018-7198 in October CMS?
To fix CVE-2018-7198 in October CMS, you should upgrade to version 1.4.1 of the RainLab Blog Plugin or later.
Are there any references for CVE-2018-7198?
Yes, you can find references for CVE-2018-7198 at the following links: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-7198), [Exploit-DB](https://www.exploit-db.com/exploits/44144/), [SecurityWarrior9 Blog](http://securitywarrior9.blogspot.com/2018/02/html-injection-october-cms.html).