CVE-2018-18416 | LANGO Codeigniter Multilingual Script 1.0 Upload admin/settings/update site_name cross site scripting (ID 149841 / EDB-45672)
A vulnerability was found in LANGO Codeigniter Multilingual Script 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file admin/settings/update of the component Upload Handler. The manipulation of the argument site_name as part of Parameter leads to cross site scripting.
This vulnerability is handled as CVE-2018-18416. The attack may be launched remotely. Furthermore, there is an exploit available.