CVE-2018-11512

Published
View on NVD ↗
CVSS v3
N/A
CVSS v2
3.5
LOW
Affected
1
PROJECT

Description

Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to admin/settings/general.

Innovative CMS in PHP to easily build a website
GitHubGitHub
31