CVE-2018-7261
MEDIUMRadiant CMS 1.1.4 - Stored Cross-Site Scripting in Personal Preferences and Configuration
Title source: llmDescription
There are multiple Persistent XSS vulnerabilities in Radiant CMS 1.1.4. They affect Personal Preferences (Name and Username) and Configuration (Site Title, Dev Site Domain, Page Parts, and Page Fields).
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/103080
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/541798/100/0/threaded
Scores
CVSS v3
5.4
EPSS
0.0019
EPSS Percentile
41.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
radiantcms/radiant_cms
1.1.4
rubygems/radiant
RubyGems
Published
Feb 21, 2018
Tracked Since
Feb 18, 2026