Vulnerability Details CVE-2018-1000868
WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can result in Javascript execution in the user's browser, injection of malicious markup into the page. This attack appear to be exploitable via The victim user must click a malicous link. This vulnerability appears to have been fixed in after commit 256a5f9d3eafbc477dcf77c7682446cc4b449c7f.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 65.5%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2018-1000868
-
cpe:2.3:a:webidsupport:webid:1.0.3
-
cpe:2.3:a:webidsupport:webid:1.0.4
-
cpe:2.3:a:webidsupport:webid:1.0.5
-
cpe:2.3:a:webidsupport:webid:1.0.6
-
cpe:2.3:a:webidsupport:webid:1.1.0
-
cpe:2.3:a:webidsupport:webid:1.1.1
-
cpe:2.3:a:webidsupport:webid:1.1.2
-
cpe:2.3:a:webidsupport:webid:1.2.0
-
cpe:2.3:a:webidsupport:webid:1.2.1
-
cpe:2.3:a:webidsupport:webid:1.2.2