5.4
CVSSv3

CVE-2018-16358

Published: 02/09/2018 Updated: 24/10/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear up to and including 2.14.1 allows remote authenticated users to upload HTML content containing an XSS payload with the file extension .ahtml.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dotclear dotclear