CVE-2018-9169: XSS
Published Apr 15, 2018
·Updated
Z-BlogPHP 1.5.1 has XSS via the zbusers/plugin/AppCentre/pluginedit.php appid parameter. The component must be accessed directly by an administrator, or through CSRF.
Affected Software
1 affected component
ZblogCN Z-blogphp=1.5.1
Event History
Apr 15, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Apr 16, 2018
Data Sourced
via NVD·09:58 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for Z-BlogPHP 1.5.1?
The vulnerability ID for Z-BlogPHP 1.5.1 is CVE-2018-9169.
2
What is the severity level of CVE-2018-9169?
The severity level of CVE-2018-9169 is medium.
3
How can an attacker exploit CVE-2018-9169?
An attacker can exploit CVE-2018-9169 by injecting XSS (cross-site scripting) payload through the app_id parameter in the zb_users/plugin/AppCentre/plugin_edit.php file.
4
Who can be affected by CVE-2018-9169?
CVE-2018-9169 can affect administrators who access the component directly or through CSRF (Cross-Site Request Forgery).
5
Is there a fix available for CVE-2018-9169?
Yes, it is recommended to update Z-BlogPHP to a version that includes a patch for CVE-2018-9169.