vendor:
SeoChecker
by:
Ahmed Elhady Mohamed
7.5
CVSS
HIGH
Stored Cross-Site Scripting
79
CWE
Product Name: SeoChecker
Affected Version From: 1.9.2
Affected Version To: 1.9.2
Patch Exists: YES
Related CWE: CVE-2018-12093
CPE: cpe:a:soetemansoftware:seochecker:1.9.2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
Stored Cross-Site Scripting in SeoChecker Umbraco CMS Plug-in
SeoChecker Umbraco CMS Plug-in version 1.9.2 is vulnerable to stored cross-site scripting vulnerability in two parameters which are SEO title and SEO description HTML parameters fields. A low privilege authenticated user who can edit the SEO tab parameter value for any Ubmraco CMS content like an article will be able to inject a malicious code to execute arbitrary HTML and JS code in a user's browser session in the context of an affected site.
Mitigation:
Upgrade to version 1.9.3 or later