Security Advisory

CVE-2018-18361

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-10-15 15:00:00
Last updated 2024-08-05 11:08:21
Assigner mitre
State PUBLISHED

Description

An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html allows XSS via the name parameter, as demonstrated by a value beginning with home_content and containing a crafted SRC attribute of an IMG element.