CVE-2018-16358
UnknownEPSS 0.68%
Last modified
CVE-2018-16358 is a vulnerability of currently unknown severity. A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authenticated users to upload HTML content containing an XSS payload with the file extension .ahtml.. EPSS estimates a 0.68% chance of exploitation in the next 30 days.
Description
A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authenticated users to upload HTML content containing an XSS payload with the file extension .ahtml.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dotclear | Dotclear | <= 2.14.1 |
References
- https://hg.dotclear.org/dotclear/rev/d4841d6d65d6Vendor Advisory
- https://hg.dotclear.org/dotclear/rev/d4841d6d65d6Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-16358?
A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authenticated users to upload HTML content containing an XSS payload with the file extension .ahtml.
How severe is CVE-2018-16358?
Severity scoring for CVE-2018-16358 is pending analysis. The EPSS model estimates a 0.68% probability of exploitation in the next 30 days.
How do I fix CVE-2018-16358?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-16350WUZHI CMS 4.1.0 has XSS via the index.php?m=core&f=set&v=bas…
- CVE-2018-16352There is a PHP code upload vulnerability in WeaselCMS 0.3.6 …
- CVE-2018-16353An issue was discovered in FHCRM through 2018-02-11. There i…
- CVE-2018-16354An issue was discovered in FHCRM through 2018-02-11. There i…
- CVE-2018-16356An issue was discovered in PbootCMS. There is a SQL injectio…9.8
- CVE-2018-16357An issue was discovered in PbootCMS. There is a SQL injectio…9.8
- CVE-2018-16359Google gVisor before 2018-08-23, within the seccomp sandbox,…
- CVE-2018-1636Stack-based buffer overflow in oninit in IBM Informix Dynami…6.7
- CVE-2018-16361An issue was discovered in BTITeam XBTIT 2.5.4. news.php all…
- CVE-2018-16362An issue was discovered in the Source Integration plugin bef…6.1
- CVE-2018-16363The mndpsingh287 File Manager plugin V2.9 for WordPress has …
- CVE-2018-16364A serialization vulnerability in Zoho ManageEngine Applicati…8.1
Are you affected by CVE-2018-16358?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
