CVE-2018-25073

A vulnerability has been found in Newcomer1989 TSN-Ranksystem up to 1.2.6 and classified as problematic. This vulnerability affects the function getlog of the file webinterface/bot.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.2.7 is able to address this issue. The patch is identified as b3a3cd8efe2cd3bd3c5b3b7abf2fe80dbee51b77. It is recommended to upgrade the affected component. VDB-218002 is the identifier assigned to this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ts-ranksystem:tsn-ranksystem:*:*:*:*:*:*:*:*

History

14 May 2024, 05:16

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad ha sido encontrada en Newcomer1989 TSN-Ranksystem hasta 1.2.6 y clasificada como problemática. Esta vulnerabilidad afecta a la función getlog del archivo webinterface/bot.php. La manipulación conduce a cross-site scripting. El ataque se puede iniciar de forma remota. La actualización a la versión 1.2.7 puede solucionar este problema. El parche se identifica como b3a3cd8efe2cd3bd3c5b3b7abf2fe80dbee51b77. Se recomienda actualizar el componente afectado. VDB-218002 es el identificador asignado a esta vulnerabilidad.

27 Oct 2023, 20:27

Type Values Removed Values Added
CWE CWE-79

20 Oct 2023, 13:15

Type Values Removed Values Added
Summary A vulnerability has been found in Newcomer1989 TSN-Ranksystem up to 1.2.6 and classified as problematic. This vulnerability affects the function getlog of the file webinterface/bot.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.2.7 is able to address this issue. The name of the patch is b3a3cd8efe2cd3bd3c5b3b7abf2fe80dbee51b77. It is recommended to upgrade the affected component. VDB-218002 is the identifier assigned to this vulnerability. A vulnerability has been found in Newcomer1989 TSN-Ranksystem up to 1.2.6 and classified as problematic. This vulnerability affects the function getlog of the file webinterface/bot.php. The manipulation leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.2.7 is able to address this issue. The patch is identified as b3a3cd8efe2cd3bd3c5b3b7abf2fe80dbee51b77. It is recommended to upgrade the affected component. VDB-218002 is the identifier assigned to this vulnerability.
CWE CWE-79

Information

Published : 2023-01-11 14:15

Updated : 2024-05-17 01:27


NVD link : CVE-2018-25073

Mitre link : CVE-2018-25073

CVE.ORG link : CVE-2018-25073


JSON object : View

Products Affected

ts-ranksystem

  • tsn-ranksystem
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')