peter bassill · operator
$ cve CVE-2019-18839 JSON

CVE-2019-18839

9.0
CRITICAL · CVSS 3.1 · EPSS 5.4% (pctl 92)

In your normal cycle

Critical by CVSS (9), but no sign of active exploitation.

Description

FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attacker can use a user account to fully compromise the system using a POST request. When the admin visits the user information, the payload will execute. This will allow for PHP files to be written to the web root, and for code to execute on the remote server.

Scoring

CVSS9.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
EPSS5.44% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2019-11-13
Last modified2026-06-17

Affected (1)

VendorProduct
fudforumfudforum

References

→ the Explorer  ·  watch your stack  ·  NVD