Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2018-7447
HistoryFeb 24, 2018 - 2:00 a.m.

CVE-2018-7447

2018-02-2402:00:00
mitre
github.com
2

AI Score

5.8

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

mojoPortal through 2.6.0.0 is prone to multiple persistent cross-site scripting vulnerabilities because it fails to sanitize user-supplied input. The ‘Title’ and ‘Subtitle’ fields of the ‘Blog’ page are vulnerable. NOTE: The software maintainer disputes this as a vulnerability because the fields claimed to be vulnerable to XSS are only available to administrators who are supposed to have access to add scripts

AI Score

5.8

Confidence

High

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

Related for VULNRICHMENT:CVE-2018-7447