CVE-2018-14922
Summary
| CVE | CVE-2018-14922 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-14 18:29:00 UTC |
| Updated | 2018-10-11 14:50:00 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in Monstra CMS 3.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name field in the edit profile page. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 404 Page Not Found | Exploit Database | EXPLOIT-DB | www.exploit-db.com | Broken Link, Third Party Advisory, VDB Entry |
| CVE-2018-14922 : Monstra-Dev Stored Cross Site Scripting - ICSS | MISC | indiancybersecuritysolutions.com | Third Party Advisory |
| Monstra-Dev 3.0.4 Cross Site Scripting ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.