Vulnerability Description
An issue was discovered in PHPok v5.0.055. There is a Stored XSS vulnerability via the title parameter to api.php?c=post&f=save (reachable via the index.php?id=book URI).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phpok | Phpok | 5.0.055 |
Related Weaknesses (CWE)
References
- https://github.com/qinggan/phpok/issues/3ExploitIssue TrackingThird Party Advisory
- https://github.com/qinggan/phpok/issues/3ExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2018-20006?
CVE-2018-20006 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An issue was discovered in PHPok v5.0.055. There is a Stored XSS vulnerability via the title parameter to api.php?c=post&f=save (reachable via the index.php?id=book URI).
How severe is CVE-2018-20006?
CVE-2018-20006 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-20006?
Check the references section above for vendor advisories and patch information. Affected products include: Phpok Phpok.