SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-11512

Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by…

MEDIUM 4.8EPSS 2.18%

Does this matter?

Lower severity and a low EPSS score (2.18%). Track it; it rarely justifies an emergency change on its own.

Description

Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to admin/settings/general.

CVSS 3.0
4.8 MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS
2.18% probability · 81th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
creatiwity/witycms
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.