Vulnerability Details CVE-2018-7547
lyadmin 1.x has XSS via the config[WEB_SITE_TITLE] parameter to the /admin.php?s=/admin/config/groupsave.html URI.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 46.3%
CVSS Severity
CVSS v3 Score 4.8
CVSS v2 Score 3.5
Products affected by CVE-2018-7547
-
cpe:2.3:a:lingyun:lyadmin:1.0.0
-
cpe:2.3:a:lingyun:lyadmin:1.0.1
-
cpe:2.3:a:lingyun:lyadmin:1.1.0
-
cpe:2.3:a:lingyun:lyadmin:1.2.0