vendor:
October CMS
by:
Samrat Das
6.1
CVSS
MEDIUM
Stored Code Injection
Unknown
CWE
Product Name: October CMS
Affected Version From: 1.0.431
Affected Version To: Unknown
Patch Exists: No
Related CWE: CVE-2018-7198
CPE: Unknown
Platforms Tested:
2018
October CMS Stored Code Injection
The application source code is coded in a way which allows malicious crafted HTML commands to be executed without input validation
Mitigation:
Implement input validation to reject unsafe HTML input