Cross Site Scripting (XSS) in MineWebCMS v1.7.0 allows remote attackers to execute arbitrary code by injecting malicious code into the 'Title' field of the component '/admin/news'.
References
Link | Resource |
---|---|
https://github.com/MineWeb/MineWebCMS/issues/123 | Exploit Third Party Advisory |
Configurations
Information
Published : 2021-08-06 12:15
Updated : 2023-03-03 10:42
NVD link : CVE-2020-18693
Mitre link : CVE-2020-18693
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
mineweb
- minewebcms