VulnerabilityModified
CVE-2018-14541
PHP Scripts Mall Basic B2B Script 2.0.0 has Reflected and Stored XSS via the First name, Last name, Address 1, City, State, and Company name fields.
MEDIUM 5.4EPSS 0.66%
Does this matter?
Lower severity and a low EPSS score (0.66%). Track it; it rarely justifies an emergency change on its own.
Description
PHP Scripts Mall Basic B2B Script 2.0.0 has Reflected and Stored XSS via the First name, Last name, Address 1, City, State, and Company name fields.
- CVSS 3.0
- 5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.66% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- readymadeb2bscript/basic b2b
- Source
- cve@mitre.org
References
- https://gkaim.com/cve-2018-14541-vikas-chaudhary/Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/45140/Broken Link
- https://gkaim.com/cve-2018-14541-vikas-chaudhary/Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/45140/Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.