← Volver a CVEs
CVE-2017-15872
N/ADescripcion
phpwcms 1.8.9 has XSS in include/inc_tmpl/admin.edituser.tmpl.php and include/inc_tmpl/admin.newuser.tmpl.php via the username (aka new_login) field.
Detalles CVE
Puntuacion CVSS v3.1N/A
Publicado10/24/2017
Ultima modificacion4/20/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
phpwcms:phpwcms
Debilidades (CWE)
CWE-79
Referencias
https://github.com/slackero/phpwcms/commit/62c7c4a7a7de5effa0a82c89e77e53795a82e11d(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/slackero/phpwcms/commit/90ee94a474b37919161f8112f9e36c53ad70492f(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.