Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-16622

Multiple cross-site scripting (XSS) vulnerabilities in /api/content/addOne in DoraCMS v2.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) discription or (2) comments field, related to users/userAddContent.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 42.0%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2018-16622
  • Html-Js » Doracms » Version: 2.0.3
    cpe:2.3:a:html-js:doracms:2.0.3


Contact Us

Shodan ® - All rights reserved