CVE-2018-16637
https://notcve.org/view.php?id=CVE-2018-16637
Evolution CMS 1.4.x allows XSS via the page weblink title parameter to the manager/ URI. Evolution CMS 1.4.x permite Cross-Site Scripting (XSS) mediante el parámetro title en el weblink de la página en el URI manager/. • https://github.com/security-breachlock/CVE-2018-16637/blob/master/evolution_xss_stored.pdf • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2018-16638
https://notcve.org/view.php?id=CVE-2018-16638
Evolution CMS 1.4.x allows XSS via the manager/ search parameter. Evolution CMS 1.4.x permite Cross-Site Scripting (XSS) mediante el parámetro search en manager/. • https://github.com/security-breachlock/CVE-2018-16638/blob/master/evolution_xss_reflected.pdf • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •