CVE-2018-18029
MEDIUMNavigate CMS - Stored Cross-Site Scripting via Title Field in Edit Action
Title source: llmDescription
Navigate CMS has Stored XSS via the navigate.php Title field in an edit action.
References (2)
Core 2
Core References
Patch, Third Party Advisory x_refsource_confirm
https://bitbucket.org/navigatecms/navigatecms/commits/586e67ce1c43d459f6b00221fb30be26fcbfb866
Exploit, Mitigation, Third Party Advisory x_refsource_confirm
https://bitbucket.org/navigatecms/navigatecms/issues/3/stored-xss-in-navigatecms
Scores
CVSS v3
5.4
EPSS
0.0019
EPSS Percentile
40.9%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
naviwebs/navigate_cms
Published
Oct 09, 2018
Tracked Since
Feb 18, 2026