Description
Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add). This allows an attacker to insert arbitrary JavaScript as user input, which will be executed whenever the affected snippet is loaded.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-2447 | Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add). This allows an attacker to insert arbitrary JavaScript as user input, which will be executed whenever the affected snippet is loaded. |
References
| Link | Providers |
|---|---|
| https://github.com/wolfcms/wolfcms/issues/682 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T22:32:00.637Z
Reserved: 2019-03-29T00:00:00.000Z
Link: CVE-2019-10646
No data.
Status : Modified
Published: 2019-03-30T03:29:00.300
Modified: 2024-11-21T04:19:39.773
Link: CVE-2019-10646
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD