WOlfCMS WolfCMS version version 0.8.3.1 contains a Stored Cross-Site Scripting vulnerability in Layout Name (from Layout tab) that can result in low privilege user can steal the cookie of admin user and compromise the admin account. This attack appear to be exploitable via Need to enter the Javascript code into Layout Name .
References
Link Resource
https://github.com/wolfcms/wolfcms/issues/667 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-03-13T15:00:00

Updated: 2018-03-13T14:57:01

Reserved: 2018-02-21T00:00:00


Link: CVE-2018-1000084

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-03-13T15:29:01.067

Modified: 2018-04-06T12:51:20.560


Link: CVE-2018-1000084

JSON object: View

cve-icon Redhat Information

No data.

CWE