First published: Fri Jul 05 2019(Updated: )
In MiniCMS V1.10, stored XSS was found in mc-admin/post-edit.php via the content box. An attacker can use it to get a user's cookie. This is different from CVE-2018-10296, CVE-2018-16233, CVE-2018-20520, and CVE-2019-13186.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
1234n Minicms | =1.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13340 is a vulnerability in MiniCMS V1.10 that allows for stored XSS attacks via the content box, potentially allowing an attacker to access a user's cookie.
CVE-2019-13340 has a severity keyword of 'medium' and a severity value of 4.8.
CVE-2019-13340 affects all versions of MiniCMS V1.10.
An attacker can exploit CVE-2019-13340 by injecting malicious code into the content box of MiniCMS V1.10, potentially leading to the theft of user cookies.
To fix CVE-2019-13340, it is recommended to update to a patched version of MiniCMS or implement the necessary security measures to prevent XSS attacks.