CVE-2018-19464

Discuz! X3.4 allows XSS via admin.php because admincp/admincp_setting.php and templatedefaultcommonfooter.htm mishandles statcode field from third-party stats code.
References
Link Resource
https://github.com/novysodope/Discuz-X3.4/blob/master/XSS Broken Link Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:dismall:discuz!:3.4:*:*:*:*:*:*:*

Information

Published : 2018-11-22 09:29

Updated : 2020-01-17 02:21


NVD link : CVE-2018-19464

Mitre link : CVE-2018-19464

Products Affected
No products.
CWE