← Back to CVEs
CVE-2017-15872
N/ADescription
phpwcms 1.8.9 has XSS in include/inc_tmpl/admin.edituser.tmpl.php and include/inc_tmpl/admin.newuser.tmpl.php via the username (aka new_login) field.
CVE Details
CVSS v3.1 ScoreN/A
Published10/24/2017
Last Modified4/20/2025
Sourcenvd
Honeypot Sightings0
Affected Products
phpwcms:phpwcms
Weaknesses (CWE)
CWE-79
References
https://github.com/slackero/phpwcms/commit/62c7c4a7a7de5effa0a82c89e77e53795a82e11d(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/slackero/phpwcms/commit/90ee94a474b37919161f8112f9e36c53ad70492f(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.