Description
A Stored XSS vulnerability has been discovered in version 4.1.0 of AlchemyCMS via the /admin/pictures image field. NOTE: the vendor's position is that this is not a valid report: "The researcher used an authorized cookie to perform the request to a password-protected route. Without that session cookie, the request would have been rejected as unauthorized."
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-7mj4-2984-955f | Withdrawn Advisory: AlchemyCMS is vulnerable to stored XSS via the /admin/pictures image field |
References
History
Fri, 29 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-29T15:03:47.555Z
Reserved: 2018-10-14T00:00:00.000Z
Link: CVE-2018-18307
No data.
Status : Modified
Published: 2018-10-16T22:29:01.697
Modified: 2025-08-29T15:15:33.330
Link: CVE-2018-18307
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA