vendor:
Fork CMS
by:
Ismail Tasdelen
5.5
CVSS
MEDIUM
Code Injection
CWE
Product Name: Fork CMS
Affected Version From: 5.4.2000
Affected Version To: 5.4.2000
Patch Exists: YES
Related CWE:
CPE:
Platforms Tested:
2018
Fork CMS 5.4.0 – Cross-Site Scripting
In the 5.4.0 version of the Fork CMS software, HTML Injection and Stored XSS vulnerabilities were discovered via the /backend/ajax URI.
Mitigation:
Upgrade to the latest version of Fork CMS.