CVE-2017-16230

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
30/10/2017
Last modified:
20/04/2025

Description

In admin/write-post.php in Typecho through 1.1, one can log in to the background page, write a new article, and add payload in the article content, resulting in XSS via index.php/action/contents-post-edit.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:typecho:typecho:*:*:*:*:*:*:*:* 1.1 (including)