CVE-2018-9237
MEDIUMiScripts EasyCreate 3.2.1 - Stored Cross-Site Scripting in Site Description Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-9237. PoCs published by ManhNho.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in iScripts EasyCreate 3.2.1, where malicious scripts can be injected into the 'Site Description' and 'Site Title' fields. The PoC shows how an attacker can execute arbitrary JavaScript in the context of a user's session.
Description
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field.
Exploits (1)
This exploit demonstrates a stored XSS vulnerability in iScripts EasyCreate 3.2.1, where malicious scripts can be injected into the 'Site Description' and 'Site Title' fields. The PoC shows how an attacker can execute arbitrary JavaScript in the context of a user's session.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N