S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2018-12095 Scanner

CVE-2018-12095 scanner - Cross-Site Scripting (XSS) vulnerability in OEcms

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-12095
5.4
CVSS

A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerability is located in the mod parameter of info.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

OEcms v3.1 is a widely-used Content Management System (CMS) used for designing and managing websites. The product is especially popular among businesses and individuals that require a simple and efficient tool to create and manage their web pages. OEcms v3.1 comes with several features that make web designing easy and efficient, including a user-friendly interface, a variety of customizable templates, and a range of add-ons and plugins that can be used to enhance the functionality of the website.

However, despite its popularity, OEcms v3.1 has been found to have a significant vulnerability, that is, the CVE-2018-12095 vulnerability. This vulnerability can be traced to the mod parameter of info.php, and it makes the website vulnerable to Reflected Cross-Site Scripting (XSS) attacks. Hackers can exploit this vulnerability to inject malicious code into the website, which can lead to the theft of sensitive data, hijacking of user sessions, and in some cases, complete control of the website.

When attackers exploit the CVE-2018-12095 vulnerability, they can place malicious code into the website, which can be triggered when unsuspecting users visit the site. This can result in the installation of malware on the victim's device, which can spread to other devices in the network. The attacker can also use the vulnerability to steal sensitive data, such as login credentials and financial information, which can be used for identity theft and other fraudulent activities.

Thanks to the pro features of the s4e.io platform, users can quickly and easily learn about vulnerabilities in their digital assets, including the CVE-2018-12095 vulnerability in OEcms v3.1. By subscribing to our premium service, users can receive timely alerts and notifications about new vulnerabilities, as well as access to specialized tools and resources that can help them strengthen the security of their web assets.

 

REFERENCES

Solution Advice

To protect against the CVE-2018-12095 vulnerability, webmasters must take the following precautions:

  • Keep the CMS and its plugins up-to-date by applying patches and upgrades as soon as they become available.
  • Disable unnecessary plugins and modules that are not in use.
  • Install a web application firewall (WAF) that can identify and block XSS attacks.
  • Regularly perform vulnerability scans and penetration testing to identify potential security weaknesses.
  • Educate users on safe browsing habits and cybersecurity best practices, such as avoiding downloading files from unknown sources or clicking on suspicious links.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-12095 scanner - Cross-Site Scripting (XSS) vulnerability in OEcms | S4E