XSS Vulnerability in WeCenter 3.2.0 - 3.2.2 via htmlspecialchars_decode Function

XSS Vulnerability in WeCenter 3.2.0 - 3.2.2 via htmlspecialchars_decode Function

CVE-2018-19083 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:P/A:N

WeCenter 3.2.0 through 3.2.2 has XSS in the views/default/question/index.tpl.html htmlspecialchars_decode function via the /?/publish/ajax/publish_question/ question_content parameter.

Learn more about our Web Application Penetration Testing UK.