CVE-2018-7261

There are multiple Persistent XSS vulnerabilities in Radiant CMS 1.1.4. They affect Personal Preferences (Name and Username) and Configuration (Site Title, Dev Site Domain, Page Parts, and Page Fields).
References
Link Resource
http://www.securityfocus.com/archive/1/541798/100/0/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/103080 Third Party Advisory VDB Entry
http://www.securityfocus.com/archive/1/541798/100/0/threaded Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/103080 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:radiantcms:radiant_cms:1.1.4:*:*:*:*:*:*:*

History

21 Nov 2024, 04:11

Type Values Removed Values Added
References () http://www.securityfocus.com/archive/1/541798/100/0/threaded - Third Party Advisory, VDB Entry () http://www.securityfocus.com/archive/1/541798/100/0/threaded - Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/103080 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/103080 - Third Party Advisory, VDB Entry

Information

Published : 2018-02-21 16:29

Updated : 2024-11-21 04:11


NVD link : CVE-2018-7261

Mitre link : CVE-2018-7261

CVE.ORG link : CVE-2018-7261


JSON object : View

Products Affected

radiantcms

  • radiant_cms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')