vendor:
BigTree CMS
by:
Ismail Tasdelen
6.1
CVSS
MEDIUM
Cross-site Scripting
79
CWE
Product Name: BigTree CMS
Affected Version From: 4.2.23
Affected Version To: 4.2.23
Patch Exists: YES
Related CWE: CVE-2018-18308
CPE: a:bigtreecms:bigtree_cms:4.2.23
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
BigTree CMS 4.2.23 – Cross-Site Scripting
In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload area). An attacker can exploit this vulnerability by sending a malicious HTTP POST request with a specially crafted filename parameter.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to update to the latest version of BigTree CMS.