CVE-2018-16358

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
02/09/2018
Last modified:
24/10/2018

Description

A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authenticated users to upload HTML content containing an XSS payload with the file extension .ahtml.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dotclear:dotclear:*:*:*:*:*:*:*:* 2.14.1 (including)


References to Advisories, Solutions, and Tools