PoC Index

CVE-2018-14922

MEDIUM 6.1EPSS 2.0%

Multiple cross-site scripting (XSS) vulnerabilities in Monstra CMS 3.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name field in the edit profile page.

CVSS v3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
1.95% chance of exploitation in the next 30 days, 79th percentile
Published
2018-08-14
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related