cve/2018/CVE-2018-15677.md
2024-06-09 00:33:16 +00:00

691 B

CVE-2018-15677

Description

The newsfeed (aka /index.php?page=viewnews) in BTITeam XBTIT 2.5.4 has stored XSS via the title of a news item. This is also exploitable via CSRF.

POC

Reference

Github

No PoCs found on GitHub currently.