Vulnerability Details CVE-2018-7447
mojoPortal through 2.6.0.0 is prone to multiple persistent cross-site scripting vulnerabilities because it fails to sanitize user-supplied input. The 'Title' and 'Subtitle' fields of the 'Blog' page are vulnerable. NOTE: The software maintainer disputes this as a vulnerability because the fields claimed to be vulnerable to XSS are only available to administrators who are supposed to have access to add scripts
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 45.7%
CVSS Severity
CVSS v3 Score 4.8
CVSS v2 Score 3.5
Products affected by CVE-2018-7447
-
cpe:2.3:a:mojoportal:mojoportal:2.4.0.9
-
cpe:2.3:a:mojoportal:mojoportal:2.4.1.0
-
cpe:2.3:a:mojoportal:mojoportal:2.5.0.0
-
cpe:2.3:a:mojoportal:mojoportal:2.6.0.0