peter bassill · operator
$ cve CVE-2018-11512 JSON

CVE-2018-11512 EXPLOIT

4.8
MEDIUM · CVSS 3.0 · EPSS 2.1% (pctl 81)

Patch early

A public exploit exists.

Description

Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to admin/settings/general.

Scoring

CVSS4.8 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS2.1% — more likely to be exploited than 81% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2018-05-28
Last modified2026-06-17

Affected (1)

VendorProduct
creatiwitywitycms

Public exploits

SourceTitleDate
exploit-dbwityCMS 0.6.1 - Cross-Site Scripting2018-05-28

References

→ the Explorer  ·  watch your stack  ·  NVD