CVE-2018-9147: XSS
Published Mar 30, 2018
·Updated
Cross-site scripting (XSS) vulnerabilities in version 7.5.7 of Gespage software allow remote attackers to inject arbitrary web script or HTML via the email, passwd, and repasswd parameters to webapp/users/userreg.jsp.
Affected Software
1 affected component
Gespage Gespage=7.5.7
Event History
Mar 30, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-9147?
CVE-2018-9147 is classified as a high-severity cross-site scripting vulnerability.
2
How do I fix CVE-2018-9147?
To fix CVE-2018-9147, it is recommended to upgrade Gespage to a version that is not affected by this vulnerability.
3
What software is affected by CVE-2018-9147?
CVE-2018-9147 affects version 7.5.7 of the Gespage software.
4
What types of attacks are possible with CVE-2018-9147?
CVE-2018-9147 allows remote attackers to inject arbitrary web scripts or HTML into the application.
5
What parameters are exploited in CVE-2018-9147?
CVE-2018-9147 exploits the email, passwd, and repasswd parameters in the webapp/users/user_reg.jsp file.