4.3
CVSSv2

CVE-2018-18845

Published: 21/03/2019 Updated: 27/03/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

internal/advanced_comment_system/index.php and internal/advanced_comment_system/admin.php in Advanced Comment System, version 1.0, contain a reflected cross-site scripting vulnerability via ACS_path. A remote unauthenticated attacker could potentially exploit this vulnerability to supply malicious HTML or JavaScript code to a vulnerable web application, which is then reflected back to the victim and executed by the web browser. The product is discontinued.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

advanced comment system project advanced comment system 1.0

Exploits

Advanced Comment System version 10 suffers from a cross site scripting vulnerability ...

Mailing Lists

I thought I had reported it but not, better late than never <!-- # Exploit Title: Cross Site Scripting in Advanced comment system v10 # Date: 29-10-2018 # Exploit Author: Rafael Pedrero # Vendor Homepage: wwwplohnicom # Software Link: wwwplohnicom/wb/content/php/download/Advanced_comment_system_1-0zip, webarchiveo ...