A Stored XSS vulnerability has been discovered in version 4.1.0 of AlchemyCMS via the /admin/pictures image field.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/149787/Alchemy-CMS-4.1-Stable-Cross-Site-Scripting.html | Exploit Third Party Advisory VDB Entry |
Configurations
Information
Published : 2018-10-16 15:29
Updated : 2018-11-21 12:58
NVD link : CVE-2018-18307
Mitre link : CVE-2018-18307
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
alchemy-cms
- alchemy_cms