1 results (0.005 seconds)
CVSS: 5.4EPSS: 0%CPEs: 1EXPL: 1
CVE-2018-12429
https://notcve.org/view.php?id=CVE-2018-12429
18 Jul 2018 — JEESNS through 1.2.1 allows XSS attacks by ordinary users who publish articles containing a crafted payload in order to capture an administrator cookie. JEESNS hasta la versión 1.2.1 permite ataques Cross-Site Scripting (XSS) por parte de usuarios ordinarios que publican artículos que contienen una carga útil manipulada para capturar una cookie de administrador. • http://www.03sec.com/3218.shtml • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •