4.8
CVSSv3

CVE-2018-16805

Published: 10/09/2018 Updated: 09/11/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

In b3log Solo 2.9.3, XSS in the Input page under the Publish Articles menu, with an ID of linkAddress stored in the link JSON field, allows remote malicious users to inject arbitrary Web scripts or HTML via a crafted site name provided by an administrator.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

b3log solo 2.9.3