vendor:
Monstra CMS
by:
Wenming Jiang
4.8
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: Monstra CMS
Affected Version From: 3.0.4
Affected Version To: 3.0.4
Patch Exists: YES
Related CWE: CVE-2018-10109
CPE: a:monstra:monstra:3.0.4
Platforms Tested: Mac
2018
Monstra cms 3.0.4 – Persitent Cross-Site Scripting
Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload in the content section of a new page in the blog catalog.
Mitigation:
Update Monstra CMS to a version that has fixed the vulnerability.