First published: Sat Feb 24 2018(Updated: )
** DISPUTED ** mojoPortal through 2.6.0.0 is prone to multiple persistent cross-site scripting vulnerabilities because it fails to sanitize user-supplied input. The 'Title' and 'Subtitle' fields of the 'Blog' page are vulnerable. NOTE: The software maintainer disputes this as a vulnerability because the fields claimed to be vulnerable to XSS are only available to administrators who are supposed to have access to add scripts.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MojoPortal | <=2.6.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-7447.
The severity of CVE-2018-7447 is medium with a severity value of 4.8.
The software affected by CVE-2018-7447 is mojoPortal through version 2.6.0.0.
CVE-2018-7447 is a persistent cross-site scripting vulnerability.
To fix CVE-2018-7447, make sure to sanitize user-supplied input in the 'Title' and 'Subtitle' fields of the 'Blog' page in mojoPortal.