4.8
CVSSv3

CVE-2018-11332

Published: 24/05/2018 Updated: 25/06/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 allows remote malicious users to inject arbitrary web script or HTML via a crafted site name to the manager/processors/save_settings.processor.php file.

Vulnerable Product Search on Vulmon Subscribe to Product

clippercms clippercms 1.3.3

Exploits

# Exploit Title: ClipperCMS 133 Persistent XSS on 'Site name' field # Date: 05/27/2018 # Exploit Author: Nathu Nandwani # Website: nandtechco/ # Vendor Homepage: wwwclippercmscom/ # Software Link: githubcom/ClipperCMS/ClipperCMS/releases/tag/clipper_133 # Version: 133 # Tested on: Windows 10 x64 (XAMPP, Chrome) # CVE ...
Clipper CMS version 133 suffers from a cross site scripting vulnerability ...