An issue was discovered in Navigate CMS 2.8 and 2.9 r1433. The query parameter fid on the resource navigate.php does not perform sufficient data validation and/or encoding, making it vulnerable to reflected XSS.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://cxsecurity.com/issue/WLB-2018090182 | third party advisory |
https://blog.sean-wright.com/navigate-cms/ | third party advisory exploit |