CVE-2018-18307
MEDIUMAlchemyCMS 4.1.0 - Stored Cross-Site Scripting via Admin Pictures Image Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-18307. PoCs published by Ismail Tasdelen.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in AlchemyCMS 4.1 via the /admin/pictures image field. The payload is injected through the filename parameter of a multipart/form-data POST request.
Description
A Stored XSS vulnerability has been discovered in version 4.1.0 of AlchemyCMS via the /admin/pictures image field. NOTE: the vendor's position is that this is not a valid report: "The researcher used an authorized cookie to perform the request to a password-protected route. Without that session cookie, the request would have been rejected as unauthorized."
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in AlchemyCMS 4.1 via the /admin/pictures image field. The payload is injected through the filename parameter of a multipart/form-data POST request.
References (5)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N