The CATALooK.netStore module through 7.2.8 for DNN (formerly DotNetNuke) allows XSS via the /ViewEditGoogleMaps.aspx PortalID or CATSkin parameter, or the /ImageViewer.aspx link or desc parameter.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://cxsecurity.com/issue/WLB-2018040120 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2018-04-16T19:00:00Z
Updated: 2024-09-16T18:02:46.586Z
Reserved: 2018-04-16T00:00:00Z
Link: CVE-2018-10138
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-04-16T20:29:00.207
Modified: 2024-11-21T03:40:54.663
Link: CVE-2018-10138
Redhat
No data.