Medium severity6.1NVD Advisory· Published Sep 5, 2018· Updated Jun 17, 2026
CVE-2018-15677
CVE-2018-15677
Description
The newsfeed (aka /index.php?page=viewnews) in BTITeam XBTIT 2.5.4 has stored XSS via the title of a news item. This is also exploitable via CSRF.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=2.5.4+ 1 more
- (no CPE)range: <=2.5.4
- (no CPE)range: =2.5.4
Patches
Vulnerability mechanics
References
2- github.com/btiteam/xbtit/pull/58nvdPatchThird Party Advisory
- rastating.github.io/xbtit-multiple-vulnerabilities/nvdExploitPatchThird Party Advisory
News mentions
0No linked articles in our index yet.