Security Advisory

CVE-2018-16249

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-06-20 13:54:12
Last updated 2024-08-05 10:17:38
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

In Symphony before 3.3.0, there is XSS in the Title under Post. The ID "articleTitle" of this is stored in the "articleTitle" JSON field, and executes a payload when accessing the /member/test/points URI, allowing remote attacks. Any Web script or HTML can be inserted by an admin-authenticated user via a crafted web site name.