Files
CVEs-PoC/2018/CVE-2018-18290.md
T
2024-08-05 18:41:32 +00:00

747 B

CVE-2018-18290

Description

** DISPUTED ** An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html&name=home_content allows XSS via the HTML Source Editor. NOTE: the vendor disputes this because the form requires administrator privileges, and entering JavaScript is supported functionality.

POC

Reference

No PoCs from references.

Github