cve/2018/CVE-2018-15677.md
2024-06-18 02:51:15 +02:00

628 B

CVE-2018-15677

Description

The newsfeed (aka /index.php?page=viewnews) in BTITeam XBTIT 2.5.4 has stored XSS via the title of a news item. This is also exploitable via CSRF.

POC

Reference

Github

No PoCs found on GitHub currently.