CVE-2018-16978
Monstra CMS V3.0.4 has XSS when ones tries to register an account with a crafted password parameter to users/registration, a different vulnerability than CVE-2018-11473.
- Affected products
- Monstra Cms
- Monstra
- = 3.0.4
- Fix
- Available
- CVSS 3.0
- 6.1 MEDIUM
- EPSS
- 0.9% (56th percentile)
- Weakness
- CWE-79
- NVD status
- Modified
- Published
- 2018-09-12
CVE-2018-16978 at NVD
No indexed exploits for CVE-2018-16978 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2018-16978 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.