Vulnerability Description
Zend.To version Prior to 5.15-1 contains a Cross Site Scripting (XSS) vulnerability in The verify.php page that can result in An attacker could execute arbitrary Javascript code in the context of the victim's browser.. This attack appear to be exploitable via HTTP POST request. This vulnerability appears to have been fixed in 5.16-1 Beta.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zend | Zendto | < 5.15-1 |
Related Weaknesses (CWE)
References
- https://zend.to/changelog.phpRelease NotesVendor Advisory
- https://zend.to/changelog.phpRelease NotesVendor Advisory
FAQ
What is CVE-2018-1000841?
CVE-2018-1000841 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Zend.To version Prior to 5.15-1 contains a Cross Site Scripting (XSS) vulnerability in The verify.php page that can result in An attacker could execute arbitrary Javascript code in the context of the ...
How severe is CVE-2018-1000841?
CVE-2018-1000841 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1000841?
Check the references section above for vendor advisories and patch information. Affected products include: Zend Zendto.