CVE-2019-9110: XSS
Published Feb 25, 2019
·Updated
XSS exists in WUZHI CMS 4.1.0 via index.php?m=content&f=postinfo&v=listing&setiframe=[XSS] to coreframe/app/content/postinfo.php.
Affected Software
2 affected components
Wuzhicms Wuzhi Cms=4.1.0
Wuzhicms Wuzhicms=4.1.0
Event History
Feb 25, 2019
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Data Sourced
via NVD·01:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2019-9110?
CVE-2019-9110 is a Cross-Site Scripting (XSS) vulnerability in WUZHI CMS 4.1.0.
2
How does the XSS vulnerability in WUZHI CMS 4.1.0 occur?
The XSS vulnerability in WUZHI CMS 4.1.0 occurs when accessing the index.php?m=content&f=postinfo&v=listing&set_iframe= URL with an XSS payload.
3
What is the severity of CVE-2019-9110?
The severity of CVE-2019-9110 is medium, with a CVSS score of 6.1.
4
How can I fix the XSS vulnerability in WUZHI CMS 4.1.0?
To fix the XSS vulnerability in WUZHI CMS 4.1.0, it is recommended to upgrade to a patched version released by WUZHI CMS.
5
Where can I find more information about CVE-2019-9110?
More information about CVE-2019-9110 can be found at the following references: [1] [2]