5.4
CVSSv3

CVE-2018-12094

Published: 11/06/2018 Updated: 01/08/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote malicious users to inject arbitrary web script or HTML via the id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

dimofinf dimofinf cms 3.0.0

Exploits

# Title: Dimofinf CMS 300 - Cross-Site Scripting # Author: Felipe "Renzi" Gabriel # Date: 2018-06-13 # Software: Dimofinf CMS Version 300 # CVE: CVE-2018-12094 # A Reflected Cross-Site Scripting web vulnerability has been discovered in the "Dimofinf CMS" web-application # The vulnerability is located in the 'id' parameter of the`newsphp` ac ...
Dimofinf CMS version 300 suffers from a cross site scripting vulnerability ...