CVE-2018-18361
15.10.2018, 15:29
An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html allows XSS via the name parameter, as demonstrated by a value beginning with home_content and containing a crafted SRC attribute of an IMG element.
Vendor | Product | Version |
---|---|---|
nconsulting | nc-cms | 𝑥 ≤ 2017-03-10 |
𝑥
= Vulnerable software versions