Vulnerability Details CVE-2018-14777
An issue was discovered in DataLife Engine (DLE) through 13.0. An attacker can use XSS (related to the /addnews.html and /index.php?do=addnews URIs) to send a malicious script to unsuspecting Admins or users.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.1%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2018-14777
-
cpe:2.3:a:dleviet:datalife_engine:13.0
-
cpe:2.3:a:dleviet:datalife_engine:9.7