3.5
CVSSv2

CVE-2018-18416

Published: 19/10/2018 Updated: 04/12/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 4.8 | Impact Score: 2.7 | Exploitability Score: 1.7
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

LANGO Codeigniter Multilingual Script 1.0 has XSS in the input and upload sections, as demonstrated by the site_name parameter to the admin/settings/update URI.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pokkho lango 1.0

Exploits

# Exploit Title: LANGO Codeigniter Multilingual Script 10 - Cross-Site Scripting # Date: 2018-10-16 # Exploit Author: Ismail Tasdelen # Vendor Homepage: pokkhocom/lango/ # Software Link : pokkhocom/lango/auth/login # Software : LANGO - Codeigniter Multilingual Script # Version : 10 # Vulernability Type : Code Injection # Vulenrabi ...
LANGO Codeigniter Multilingual Script version 10 suffers from html injection and cross site scripting vulnerabilities ...
LANGO Codeigniter Multilingual Script version 10 suffers from a cross site scripting vulnerability ...