CVE-2018-1000521

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
26/06/2018
Last modified:
27/08/2018

Description

BigTree-CMS contains a Cross Site Scripting (XSS) vulnerability in /users/create that can result in The low-privileged users can use this vulnerability to attack high-privileged(Developer) users.. This attack appear to be exploitable via no. This vulnerability appears to have been fixed in after commit b652cfdc14d0670c81ac4401ad5a04376745c279.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bigtreecms:bigtree_cms:4.2.21:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools