Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-11208

Опубликовано: 16 мая 2018
Источник: nvd
CVSS3: 4.8
CVSS2: 3.5
EPSS Низкий

Описание

An issue was discovered in Z-BlogPHP 2.0.0. There is a persistent XSS that allows remote attackers to inject arbitrary web script or HTML into background web site settings via the "copyright information office" field. NOTE: the vendor indicates that the product was not intended to block this type of XSS by a user with the admin privilege

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zblogcn:z-blogphp:2.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 49%
0.00258
Низкий

4.8 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
github
больше 3 лет назад

** DISPUTED ** An issue was discovered in Z-BlogPHP 2.0.0. There is a persistent XSS that allows remote attackers to inject arbitrary web script or HTML into background web site settings via the "copyright information office" field. NOTE: the vendor indicates that the product was not intended to block this type of XSS by a user with the admin privilege.

EPSS

Процентиль: 49%
0.00258
Низкий

4.8 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79