mojoPortal through 2.6.0.0 is prone to multiple persistent cross-site scripting vulnerabilities because it fails to sanitize user-supplied input. The 'Title' and 'Subtitle' fields of the 'Blog' page are vulnerable. NOTE: The software maintainer disputes this as a vulnerability because the fields claimed to be vulnerable to XSS are only available to administrators who are supposed to have access to add scripts
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T06:24:11.904Z

Reserved: 2018-02-23T00:00:00

Link: CVE-2018-7447

cve-icon Vulnrichment

Updated: 2024-08-05T06:24:11.904Z

cve-icon NVD

Status : Modified

Published: 2018-02-24T02:29:06.847

Modified: 2024-11-21T04:12:09.207

Link: CVE-2018-7447

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.