
We found results for “”
CVE-2018-6464
Good to know:


Date: January 31, 2018
Simditor v2.3.11 allows XSS via crafted use of svg/onload=alert in a TEXTAREA element, as demonstrated by Firefox 54.0.1.
Language: JS
Severity Score
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix

Upgrade Version
Upgrade to version houdunwang/hdcms - dev-dependabot/npm_and_yarn/acorn-6.4.1;houdunwang/hdcms - dev-dependabot/npm_and_yarn/Modules/Article/dns-packet-1.3.4;houdunwang/hdcms - dev-dependabot/composer/symfony/http-foundation-4.4.7;jayson755/loid-frame - no_fix;heycommunity/heycommunity-backend - dev-devs/composer-script;heycommunity/heycommunity-backend - dev-fix/get-status-code;heycommunity/heycommunity-backend - dev-migration;heycommunity/heycommunity-backend - dev-analysis-2221eB;mobilecart/adminbundle - no_fix;zxp/yii2-simditor - no_fix;myqqiu/laracms-framework - no_fix;flex/blog - dev-dependabot/npm_and_yarn/url-parse-1.5.10;flex/blog - dev-dependabot/npm_and_yarn/follow-redirects-1.14.8;flex/blog - 2.0.x-dev;flex/blog - dev-dependabot/npm_and_yarn/ssri-6.0.2;flex/blog - no_fix;flex/blog - v1.6.0;flex/blog - dev-dependabot/npm_and_yarn/url-parse-1.5.3;calven/simditor - no_fix;wanglelecc/laracms-framework - v1.0.0;jcbt/simditor - 1.1;ibrand/wechat-backend - no_fix;ibrand/wechat-backend - v1.0.0;wanglelecc/laracms - no_fix;wanglelecc/laracms - 2.x-dev;wanglelecc/laracms - v1.0.0;perryyo/larakit - 0.0.1;lubobill1990/yii2-simditor - v0.0.4;lubobill1990/yii2-simditor - no_fix;zxc5802316/larabbs - no_fix;ptadmin/admin - v0.0.2;hongyukeji/laravel-simditor - v1.0.0;poppy/system - 2.0.x-dev;jxlwqq/simditor - no_fix;simditor - 2.3.22;snowlyg/laracms-framework - no_fix;anxu/yii2-simditor - no_fix;felix33/yii2-simditor - v1.0.0;beastphp/easy-admin-bundle - 1.0.0;org.webjars.bower:simple-uploader:no_fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | CHANGED |
Confidentiality (C): | LOW |
Integrity (I): | LOW |
Availability (A): | NONE |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | MEDIUM |
Authentication (AU): | NONE |
Confidentiality (C): | NONE |
Integrity (I): | PARTIAL |
Availability (A): | NONE |
Additional information: |