CVE Feed

    Dashboard / CVE / CVE-2018-13000

    CVE-2018-13000

    An XSS issue was discovered in Advanced Electron Forum (AEF) v1.0.9. A persistent XSS vulnerability is located in the `FTP Link` element of the `Private Message` module. The editor of the private message module allows inserting links without sanitizing the content. This allows remote attackers to inject malicious script code payloads as a private message (aka pmbody). The injection point is the editor ftp link element and the execution point occurs in the message body context on arrival. The request method to inject is POST with restricted user privileges.

    Published:Jun 29, 2018
    Last Modified:Nov 21, 2024
    EPS:Jun 29, 2018
    EPSS Score:0.00361
    CVSS Score:4.8

    Affected Products

    Vendor
    Anelectron
    Product
    Advanced Electron Forum

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High