CVE-2019-9108: XSS
Published Feb 25, 2019
·Updated
XSS exists in WUZHI CMS 4.1.0 via index.php?m=core&f=map&v=baidumap&x=[XSS]&y=[XSS] to coreframe/app/core/map.php.
Affected Software
1 affected component
Wuzhicms Wuzhicms=4.1.0
Event History
Feb 25, 2019
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2019-9108?
CVE-2019-9108 is a vulnerability in WUZHI CMS 4.1.0 that allows for XSS (Cross-Site Scripting) attacks.
2
How can I exploit CVE-2019-9108?
You can exploit CVE-2019-9108 by manipulating the 'x' and 'y' parameters in the index.php?m=core&f=map&v=baidumap URL to inject malicious scripts.
3
What is the severity of CVE-2019-9108?
CVE-2019-9108 has a severity rating of 6.1 (medium).
4
How do I fix CVE-2019-9108?
To fix CVE-2019-9108, update WUZHI CMS to version 4.1.1 or later, as this vulnerability has been patched.
5
Where can I find more information about CVE-2019-9108?
You can find more information about CVE-2019-9108 on the GitHub repository of WUZHI CMS and the provided references.