Vulnerability Description
A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authenticated users to upload HTML content containing an XSS payload with the file extension .ahtml.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dotclear | Dotclear | <= 2.14.1 |
Related Weaknesses (CWE)
References
- https://hg.dotclear.org/dotclear/rev/d4841d6d65d6Vendor Advisory
- https://hg.dotclear.org/dotclear/rev/d4841d6d65d6Vendor Advisory
FAQ
What is CVE-2018-16358?
CVE-2018-16358 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authenticated users to upload HTML content containing an XSS payl...
How severe is CVE-2018-16358?
CVE-2018-16358 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-16358?
Check the references section above for vendor advisories and patch information. Affected products include: Dotclear Dotclear.