Vulnerability Description
WBCE v1.1.11 is vulnerable to reflected XSS via the "begriff" POST parameter in /admin/admintools/tool.php?tool=user_search
CVSS Score
4.8
MEDIUM
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wbce | Wbce Cms | 1.1.11 |
Related Weaknesses (CWE)
References
- https://github.com/WBCE/WBCE_CMS/commit/0da620016aec17ac2d2f3a22c55ab8c2b55e691ePatchThird Party Advisory
- https://github.com/WBCE/WBCE_CMS/commit/0da620016aec17ac2d2f3a22c55ab8c2b55e691ePatchThird Party Advisory
FAQ
What is CVE-2017-1000213?
CVE-2017-1000213 is a vulnerability with a CVSS score of 4.8 (MEDIUM). WBCE v1.1.11 is vulnerable to reflected XSS via the "begriff" POST parameter in /admin/admintools/tool.php?tool=user_search
How severe is CVE-2017-1000213?
CVE-2017-1000213 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-1000213?
Check the references section above for vendor advisories and patch information. Affected products include: Wbce Wbce Cms.