CVE-2018-5370

MEDIUM

BizLogic xnami 1.0 - Cross-Site Scripting via Comment Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-5370. PoCs published by Dennis Veninga.

AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in BizLogic xnami 1.0 via the comment parameter in an addComment action. Attackers can inject malicious JavaScript code, which executes when users visit the media page, potentially leading to session hijacking.

Description

BizLogic xnami 1.0 has XSS via the comment parameter in an addComment action to the /media/ajax URI.

Exploits (1)

exploitdb WORKING POC
by Dennis Veninga · textwebappsphp
https://www.exploit-db.com/exploits/43535

This exploit demonstrates a persistent XSS vulnerability in BizLogic xnami 1.0 via the comment parameter in an addComment action. Attackers can inject malicious JavaScript code, which executes when users visit the media page, potentially leading to session hijacking.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: BizLogic xnami 1.0
No auth needed
Prerequisites: Access to the comment system on the target site
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/43535/

Scores

CVSS v3 6.1
EPSS 0.0219
EPSS Percentile 80.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
bizlogicdev/xnami 1.0
Published Jan 16, 2018
Tracked Since Feb 18, 2026