CVE-2018-5370
MEDIUMBizLogic xnami 1.0 - Cross-Site Scripting via Comment Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-5370. PoCs published by Dennis Veninga.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in BizLogic xnami 1.0 via the comment parameter in an addComment action. Attackers can inject malicious JavaScript code, which executes when users visit the media page, potentially leading to session hijacking.
Description
BizLogic xnami 1.0 has XSS via the comment parameter in an addComment action to the /media/ajax URI.
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in BizLogic xnami 1.0 via the comment parameter in an addComment action. Attackers can inject malicious JavaScript code, which executes when users visit the media page, potentially leading to session hijacking.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N