Cross-Site Scripting (XSS) Vulnerability in Maccms through 8.0 via site_keywords Field

Cross-Site Scripting (XSS) Vulnerability in Maccms through 8.0 via site_keywords Field

CVE-2018-19465 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:P/A:N

Maccms through 8.0 allows XSS via the site_keywords field to index.php?m=system-config because of tpl/module/system.php and tpl/html/system_config.html, related to template/paody/html/vod_index.html.

Learn more about our Cms Pen Testing.