Sploitus

CVE-2018-14922

3 known exploits for CVE-2018-14922

Multiple cross-site scripting (XSS) vulnerabilities in Monstra CMS 3.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name field in the edit profile page.

Affected products
Monstra Cms
Monstra
= 3.0.4
Fix
Available
CVSS 3.0
6.1 MEDIUM
EPSS
2.0% (79th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2018-08-14
CVE-2018-14922 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2018-14922

Proof-of-concept code and exploit modules indexed by Sploitus