Cross-Site Scripting (XSS) Vulnerability in baserCMS 4.1.4

Cross-Site Scripting (XSS) Vulnerability in baserCMS 4.1.4

CVE-2018-18943 · LOW Severity

AV:N/AC:M/AU:S/C:N/I:P/A:N

An issue was discovered in baserCMS before 4.1.4. In the Register New Category feature of the Upload menu, the category name can be used for XSS via the data[UploaderCategory][name] parameter to an admin/uploader/uploader_categories/edit URI.

Learn more about our Cms Pen Testing.