ZeroHour

CVE-2019-15228

PoC ×2
CVSS 3.0
5.4 medium
EPSS
<1%p52
Published
()
Modified
Description

FUEL CMS 1.4.4 has XSS in the Create Blocks section of the Admin console. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account but can also impact unauthenticated visitors.

Vendors
thedaylightstudio
Products
fuel cms
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.