TROYANOSYVIRUS
Voltar para CVEs

CVE-2018-18307

N/A

Descricao

A Stored XSS vulnerability has been discovered in version 4.1.0 of AlchemyCMS via the /admin/pictures image field. NOTE: the vendor's position is that this is not a valid report: "The researcher used an authorized cookie to perform the request to a password-protected route. Without that session cookie, the request would have been rejected as unauthorized."

This product uses data from the NVD API but is not endorsed or certified by the NVD.