CVE-2018-8078: XSS
Published Mar 13, 2018
·Updated
YzmCMS 3.7 has Stored XSS via the title parameter to advertisement/adver/edit.html.
Affected Software
1 affected component
YzmCMS YzmCMS=3.7
Event History
Mar 13, 2018
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Data Sourced
via NVD·08:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-8078?
CVE-2018-8078 is considered a medium severity vulnerability due to its potential for exploitation through stored XSS.
2
How do I fix CVE-2018-8078?
To fix CVE-2018-8078, it is recommended to sanitize input in the title parameter to prevent XSS attacks.
3
What software is affected by CVE-2018-8078?
CVE-2018-8078 affects YzmCMS version 3.7.
4
Can I exploit CVE-2018-8078 to execute arbitrary scripts?
Yes, CVE-2018-8078 allows attackers to execute arbitrary scripts in the context of a user's session.
5
Is CVE-2018-8078 a common vulnerability found in web applications?
Stored XSS vulnerabilities like CVE-2018-8078 are relatively common and pose significant risks if not properly mitigated.