CVE-2019-14518: XSS
Published Aug 15, 2019
·Updated
DISPUTED Evolution CMS 2.0.x allows XSS via a description and new category location in a template. NOTE: the vendor states that the behavior is consistent with the "access policy in the administration panel."
Affected Software
1 affected component
MODX Evolution Cms=2.0.0-alpha
Event History
Aug 15, 2019
CVE Published
via MITRE·03:51 PM
Data Sourced
via MITRE·03:51 PM
Description
Disputed
04:15 PM
Frequently Asked Questions
1
What is the severity of CVE-2019-14518?
The severity of CVE-2019-14518 is debated and primarily concerns potential XSS vulnerabilities in Evolution CMS.
2
How do I fix CVE-2019-14518?
To fix CVE-2019-14518, ensure that input validation and sanitization mechanisms are implemented for user-supplied data.
3
Which versions are affected by CVE-2019-14518?
CVE-2019-14518 affects Evolution CMS version 2.0.0-alpha.
4
What type of vulnerability is CVE-2019-14518?
CVE-2019-14518 is classified as a cross-site scripting (XSS) vulnerability.
5
Is the XSS behavior in CVE-2019-14518 consistent with CMS policies?
The vendor claims that the XSS behavior in CVE-2019-14518 aligns with the access policies of the administration panel.