435
VMScore

CVE-2018-10311

Published: 24/04/2018 Updated: 24/05/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A vulnerability exists in WUZHI CMS 4.1.0. There is persistent XSS that allows remote malicious users to inject arbitrary web script or HTML via the tag[pinyin] parameter to the /index.php?m=tags&f=index&v=add URI.

Vulnerable Product Search on Vulmon Subscribe to Product

wuzhicms wuzhi cms 4.1.0

Exploits

# Exploit Title: WUZHI CMS 410 XSS Vulnerability # Date: 2018-4-23 # Exploit Author: jiguang (s1@jiguangin) # Vendor Homepage: githubcom/wuzhicms/wuzhicms # Software Link: githubcom/wuzhicms/wuzhicms # Version: 410 # CVE: CVE-2018-10311 An issue was discovered in WUZHI CMS 410 (githubcom/wuzhicms/wuzhicms/issues/1 ...
Wuzhi CMS version 410 suffers from multiple cross site scripting vulnerabilities ...