CVE-2018-1999021
Last modified
CVE-2018-1999021 is a vulnerability of currently unknown severity. Gleezcms Gleez Cms version 1.3.0 contains a Cross Site Scripting (XSS) vulnerability in Profile page that can result in Inject arbitrary web script or HTML via the profile page editor. This attack appear to be exploitable via The victim must navigate to the attacker's profile page.. EPSS estimates a 0.65% chance of exploitation in the next 30 days.
Description
Gleezcms Gleez Cms version 1.3.0 contains a Cross Site Scripting (XSS) vulnerability in Profile page that can result in Inject arbitrary web script or HTML via the profile page editor. This attack appear to be exploitable via The victim must navigate to the attacker's profile page.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gleeztech | Gleezcms | 1.3.0 |
References
- https://github.com/gleez/cms/issues/797Exploit, Third Party Advisory
- https://github.com/gleez/cms/issues/797Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1999021?
How severe is CVE-2018-1999021?
How do I fix CVE-2018-1999021?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-1999015FFmpeg before commit 5aba5b89d0b1d73164d3b81764828bb8b20ff32…
- CVE-2018-1999016Pydio version 8.2.0 and earlier contains a Cross Site Script…
- CVE-2018-1999017Pydio version 8.2.0 and earlier contains a Server-Side Reque…
- CVE-2018-1999018Pydio version 8.2.1 and prior contains an Unvalidated user i…
- CVE-2018-1999019Chamilo LMS version 11.x contains an Unserialization vulnera…9.8
- CVE-2018-1999020Open Networking Foundation (ONF) ONOS version 1.13.2 and ear…
- CVE-2018-1999022PEAR HTML_QuickForm version 3.2.14 contains an eval injectio…
- CVE-2018-1999023The Battle for Wesnoth Project version 1.7.0 through 1.14.3 …
- CVE-2018-1999024MathJax version prior to version 2.7.4 contains a Cross Site…
- CVE-2018-1999025A man in the middle vulnerability exists in Jenkins TraceTro…
- CVE-2018-1999026A server-side request forgery vulnerability exists in Jenkin…
- CVE-2018-1999027An exposure of sensitive information vulnerability exists in…
Are you affected by CVE-2018-1999021?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
