vendor:
WUZHI CMS
by:
jiguang (s1@jiguang.in)
6.1
CVSS
MEDIUM
XSS
79
CWE
Product Name: WUZHI CMS
Affected Version From: 4.1.0
Affected Version To: 4.1.0
Patch Exists: YES
Related CWE: CVE-2018-10311
CPE: a:wuzhicms:wuzhicms:4.1.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
WUZHI CMS 4.1.0 XSS Vulnerability
An issue was discovered in WUZHI CMS 4.1.0 (https://github.com/wuzhicms/wuzhicms/issues/131) There is a xss vulnerability that can stealing administrator cookie, fishing attack, etc. via the tag[pinyin] parameter post to the /index.php?m=tags&f=index&v=add&&_su=wuzhicms&_menuid=?&_submenuid=?
Mitigation:
Input validation should be used to prevent XSS attacks.