CVE-2018-10109
Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload in the content section of a new page in the blog catalog.
- Affected products
- Monstra Cms
- Monstra
- = 3.0.4
- CVSS 3.0
- 4.8 MEDIUM
- EPSS
- 2.1% (81th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2018-04-14
CVE-2018-10109 at NVD
4 known exploits for CVE-2018-10109
Proof-of-concept code and exploit modules indexed by Sploitus