CVE-2018-15677
05.09.2018, 21:29
The newsfeed (aka /index.php?page=viewnews) in BTITeam XBTIT 2.5.4 has stored XSS via the title of a news item. This is also exploitable via CSRF.
Vendor | Product | Version |
---|---|---|
btiteam | xbtit | 2.5.4 |
𝑥
= Vulnerable software versions