CVE-2018-7261

MEDIUM

Radiant CMS 1.1.4 - Stored Cross-Site Scripting in Personal Preferences and Configuration

Title source: llm
STIX 2.1

Description

There are multiple Persistent XSS vulnerabilities in Radiant CMS 1.1.4. They affect Personal Preferences (Name and Username) and Configuration (Site Title, Dev Site Domain, Page Parts, and Page Fields).

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/103080
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/541798/100/0/threaded

Scores

CVSS v3 5.4
EPSS 0.0019
EPSS Percentile 41.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
radiantcms/radiant_cms 1.1.4
rubygems/radiant RubyGems
Published Feb 21, 2018
Tracked Since Feb 18, 2026