CVE-2018-14541
UnknownEPSS 0.66%
Last modified
CVE-2018-14541 is a vulnerability of currently unknown severity. PHP Scripts Mall Basic B2B Script 2.0.0 has Reflected and Stored XSS via the First name, Last name, Address 1, City, State, and Company name fields.. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
PHP Scripts Mall Basic B2B Script 2.0.0 has Reflected and Stored XSS via the First name, Last name, Address 1, City, State, and Company name fields.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Readymadeb2bscript | Basic B2b | 2.0.0 |
References
- https://gkaim.com/cve-2018-14541-vikas-chaudhary/Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/45140/Broken Link
- https://gkaim.com/cve-2018-14541-vikas-chaudhary/Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/45140/Broken Link
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-14541?
PHP Scripts Mall Basic B2B Script 2.0.0 has Reflected and Stored XSS via the First name, Last name, Address 1, City, State, and Company name fields.
How severe is CVE-2018-14541?
Severity scoring for CVE-2018-14541 is pending analysis. The EPSS model estimates a 0.66% probability of exploitation in the next 30 days.
How do I fix CVE-2018-14541?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-14529Invoxia NVX220 devices allow access to /bin/sh via escape fr…
- CVE-2018-1453IBM Security Identity Manager Virtual Appliance 7.0 allows a…8.8
- CVE-2018-14531An issue was discovered in Bento4 1.5.1-624. There is an uns…
- CVE-2018-14532An issue was discovered in Bento4 1.5.1-624. There is a heap…
- CVE-2018-14533read_tmp and write_tmp in Inteno IOPSYS allow attackers to g…
- CVE-2018-1454IBM InfoSphere Information Server 11.3, 11.5, and 11.7 could…5.9
- CVE-2018-14543There exists one NULL pointer dereference vulnerability in A…
- CVE-2018-14544There exists one invalid memory read bug in AP4_SampleDescri…
- CVE-2018-14545There exists one invalid memory read bug in AP4_SampleDescri…
- CVE-2018-14549An issue has been found in libwav through 2017-04-20. It is …
- CVE-2018-1455IBM Tivoli Application Dependency Discovery Manager 7.2.2 an…4.3
- CVE-2018-14550An issue has been found in third-party PNM decoding associat…8.8
Are you affected by CVE-2018-14541?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
