vendor:
wityCMS
by:
Nathu Nandwani
4.8
CVSS
MEDIUM
Persistent Cross-Site Scripting (XSS)
79
CWE
Product Name: wityCMS
Affected Version From: 2000.6.1
Affected Version To: 2000.6.1
Patch Exists: YES
Related CWE: CVE-2018-11512
CPE: a:witycms_project:witycms:0.6.1
Platforms Tested: Windows 10 x64 (XAMPP, Chrome)
2018
wityCMS 0.6.1 Persistent XSS on “Website’s name” field
A persistent/stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to admin/settings/general.
Mitigation:
The fix for this vulnerability can be found at: https://github.com/Creatiwity/wityCMS/commit/7967e5bf15b4d2ee6b85b56e82d7e1229147de44