VYPR
Medium severity6.1OSV Advisory· Published Jul 23, 2018· Updated Jun 17, 2026

CVE-2018-14512

CVE-2018-14512

Description

An XSS vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the form[nickname] parameter to the index.php?m=core&f=set&v=sendmail URI. When the administrator accesses the "system settings - mail server" screen, the XSS payload is triggered.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • WuzhiCMS/Wuzhicmsllm-fuzzy3 versions
    =4.1.0+ 2 more
    • (no CPE)range: =4.1.0
    • cpe:2.3:a:wuzhicms:wuzhicms:4.1.0:*:*:*:*:*:*:*
    • (no CPE)range: v2.0.1, v2.0.4, v2.0.5, …

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.