icon

We found results for “

CVE-2018-6464

Good to know:

icon
icon

Date: January 31, 2018

Simditor v2.3.11 allows XSS via crafted use of svg/onload=alert in a TEXTAREA element, as demonstrated by Firefox 54.0.1.

Language: JS

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-79

Top Fix

icon

Upgrade Version

Upgrade to version houdunwang/hdcms - dev-dependabot/npm_and_yarn/acorn-6.4.1;houdunwang/hdcms - dev-dependabot/npm_and_yarn/Modules/Article/dns-packet-1.3.4;houdunwang/hdcms - dev-dependabot/composer/symfony/http-foundation-4.4.7;jayson755/loid-frame - no_fix;heycommunity/heycommunity-backend - dev-devs/composer-script;heycommunity/heycommunity-backend - dev-fix/get-status-code;heycommunity/heycommunity-backend - dev-migration;heycommunity/heycommunity-backend - dev-analysis-2221eB;mobilecart/adminbundle - no_fix;zxp/yii2-simditor - no_fix;myqqiu/laracms-framework - no_fix;flex/blog - dev-dependabot/npm_and_yarn/url-parse-1.5.10;flex/blog - dev-dependabot/npm_and_yarn/follow-redirects-1.14.8;flex/blog - 2.0.x-dev;flex/blog - dev-dependabot/npm_and_yarn/ssri-6.0.2;flex/blog - no_fix;flex/blog - v1.6.0;flex/blog - dev-dependabot/npm_and_yarn/url-parse-1.5.3;calven/simditor - no_fix;wanglelecc/laracms-framework - v1.0.0;jcbt/simditor - 1.1;ibrand/wechat-backend - no_fix;ibrand/wechat-backend - v1.0.0;wanglelecc/laracms - no_fix;wanglelecc/laracms - 2.x-dev;wanglelecc/laracms - v1.0.0;perryyo/larakit - 0.0.1;lubobill1990/yii2-simditor - v0.0.4;lubobill1990/yii2-simditor - no_fix;zxc5802316/larabbs - no_fix;ptadmin/admin - v0.0.2;hongyukeji/laravel-simditor - v1.0.0;poppy/system - 2.0.x-dev;jxlwqq/simditor - no_fix;simditor - 2.3.22;snowlyg/laracms-framework - no_fix;anxu/yii2-simditor - no_fix;felix33/yii2-simditor - v1.0.0;beastphp/easy-admin-bundle - 1.0.0;org.webjars.bower:simple-uploader:no_fix

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

CVSS v2

Base Score:
Access Vector (AV): NETWORK
Access Complexity (AC): MEDIUM
Authentication (AU): NONE
Confidentiality (C): NONE
Integrity (I): PARTIAL
Availability (A): NONE
Additional information:

Do you need more information?

Contact Us