vendor:
ClipperCMS
by:
Nathu Nandwani
4.8
CVSS
MEDIUM
Persistent XSS
79
CWE
Product Name: ClipperCMS
Affected Version From: 1.3.2003
Affected Version To: 1.3.2003
Patch Exists: YES
Related CWE: CVE-2018-11332
CPE: a:clippercms:clippercms:1.3.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 x64 (XAMPP, Chrome)
2018
ClipperCMS 1.3.3 Persistent XSS on ‘Site name’ field
A persistent/stored cross-site scripting (XSS) vulnerability in the 'Site Name' field found in the 'site' tab under configurations in ClipperCMS 1.3.3 has been discovered because it didn't sanitize user input. It allows authenticated remote attackers to inject arbitrary web script or HTML via a crafted site name to the manager/processors/save_settings.processor.php file.
Mitigation:
See https://github.com/nathunandwani/ClipperCMS/commit/f286fbfa81dc3728dbbf6d9d817c8848edcad0b2