ZeroHour

CVE-2018-7035

PoC
CVSS 3.0
5.4 medium
EPSS
<1%p60
Published
()
Modified
Description

Cross-site scripting (XSS) vulnerability in Gleez CMS 1.2.0 and 2.0 might allow remote attackers (users) to inject JavaScript via HTML content in an editor, which will result in Stored XSS when an Administrator tries to edit the same content, as demonstrated by use of the source editor for HTML mode in an Add Blog action.

Vendors
gleezcms
Products
gleez cms
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.