Vulnerability Description
InstantCMS is a free and open source content management system. In photo upload function in the photo album page there is no input validation taking place. Due to this attackers are able to inject the XSS (Cross Site Scripting) payload and execute. This vulnerability is fixed in 2.16.3.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Instantcms | Instantcms | < 2.16.3 |
Related Weaknesses (CWE)
References
- https://github.com/instantsoft/icms2/commit/e02de2fa1850bb40c9b2050b9256c838a0eaPatch
- https://github.com/instantsoft/icms2/security/advisories/GHSA-f6cf-jg84-fw29ExploitPatchVendor Advisory
FAQ
What is CVE-2024-50348?
CVE-2024-50348 is a vulnerability with a CVSS score of 5.4 (MEDIUM). InstantCMS is a free and open source content management system. In photo upload function in the photo album page there is no input validation taking place. Due to this attackers are able to inject the...
How severe is CVE-2024-50348?
CVE-2024-50348 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-50348?
Check the references section above for vendor advisories and patch information. Affected products include: Instantcms Instantcms.