CVE-2017-16904
20.11.2017, 19:29
The Public tologin feature in admin.php in LvyeCMS through 3.1 allows XSS via a crafted username that is mishandled during later log viewing by an administrator.
Vendor | Product | Version |
---|---|---|
lvyecms_project | lvyecms | 𝑥 ≤ 3.1 |
𝑥
= Vulnerable software versions