CVE-2018-18419

MEDIUM

ARDAWAN.COM User Management 1.1 - Stored Cross-Site Scripting via Upload Filename

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-18419. PoCs published by Ismail Tasdelen.

AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in User Management 1.1 by uploading a malicious .jpg filename via a POST request to the /account URI. The payload triggers an alert when the image fails to load, confirming the vulnerability.

Description

Stored XSS has been discovered in the upload section of ARDAWAN.COM User Management 1.1, as demonstrated by a .jpg filename to the /account URI.

Exploits (1)

exploitdb WORKING POC
by Ismail Tasdelen · textwebappsphp
https://www.exploit-db.com/exploits/45686

This exploit demonstrates a stored XSS vulnerability in User Management 1.1 by uploading a malicious .jpg filename via a POST request to the /account URI. The payload triggers an alert when the image fails to load, confirming the vulnerability.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: User Management 1.1
Auth required
Prerequisites: Access to the /Cpanel/account endpoint · Valid session cookies
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/45686/
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/149850/User-Management-1.1-Cross-Site-Scripting.html

Scores

CVSS v3 5.4
EPSS 0.0164
EPSS Percentile 73.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
ardawan/user_management 1.1
Published Oct 19, 2018
Tracked Since Feb 18, 2026