Arbitrary Code Injection via Search Panel in BlackCatCMS 1.3

Arbitrary Code Injection via Search Panel in BlackCatCMS 1.3

CVE-2018-10821 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Cross-site scripting (XSS) vulnerability in backend/pages/modify.php in BlackCatCMS 1.3 allows remote authenticated users with the Admin role to inject arbitrary web script or HTML via the search panel.

Learn more about our Web App Pen Testing.