CVE-2018-1999021

MEDIUM5.4EPSS 0.21%

Gleez Cms Cross-site Scripting in Profile Page

Published: 5/14/2022Modified: 4/25/2024
Also known as:GHSA-q9g7-pff4-548r

Description

Gleezcms Gleez Cms version 1.3.0 contains a Cross Site Scripting (XSS) vulnerability in Profile page that can result in injection of arbitrary web script or HTML via the profile page editor. The victim must navigate to the attacker's profile page to exploit this vulnerability.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.4CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References (3)