Record summary

CVE-2018-10311 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit.

Description

A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the tag[pinyin] parameter to the /index.php?m=tags&f=index&v=add URI.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBWUZHI CMS 4.1.0 - 'tag[pinyin]' Cross-Site ScriptingExploitDB exploitby jiguangNot analyzed1 file
ExploitDB

PoC details

References

3