LiveActive security incident?Get immediate response
CVE Record

CVE-2018-10250: iCMS V7.0.8 has XSS via the admincp.php keywords parameter in a weixin_category action, aka a WeChat Classi...

iCMS V7.0.8 has XSS via the admincp.php keywords parameter in a weixin_category action, aka a WeChat Classified Management keyword search.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2018-10250 is a reported cross-site scripting issue in iCMS V7.0.8. A value submitted through the WeChat classified management keyword search could run script in a user’s browser. Business impact depends on who can reach that admin function; if exposed to administrators, it could support session abuse or misleading admin actions.

Executive priority

Prioritize confirmation over emergency response. The issue affects an administrative search path and has no sourced active exploitation signal, but XSS in admin tooling can still create account and data integrity risk if the panel is exposed.

Technical view

The CVE description identifies XSS in the admincp.php keywords parameter during a weixin_category action, described as WeChat Classified Management keyword search. The source bundle provides no CVSS score, CWE, patch version, or detailed affected CPEs. Treat the named iCMS V7.0.8 path as the grounded exposure indicator.

Likely exposure

Likely exposure is limited to environments running iCMS V7.0.8 where the affected admincp.php WeChat category search function is present and reachable. Public exposure is not established by the sources. Confirm whether admin access is internet-facing, restricted to trusted networks, or unused.

Exploitation context

The source bundle reports the vulnerability but does not show CISA KEV inclusion or active exploitation evidence. The public GitHub issue is the only referenced disclosure source. Evidence is sufficient to identify the vulnerable feature, but incomplete for severity, exploit prevalence, or vendor remediation status.

Researcher notes

The record is sparse: no CVSS, CWE, CPE, or official remediation metadata appears in the supplied bundle. Use the CVE description and GitHub issue as source anchors, and avoid broad product assumptions beyond iCMS V7.0.8 and the named admin action.

Mitigation direction

  • Check the iCMS project issue and vendor guidance for fixed versions or official patches.
  • Inventory and prioritize any iCMS V7.0.8 deployments.
  • Restrict access to iCMS admin interfaces to trusted users and networks.
  • Apply compensating browser and application controls where vendor fixes are unavailable.
  • Review logs for suspicious admin keyword-search activity.

Validation and detection

  • Confirm whether iCMS V7.0.8 is installed in production or staging.
  • Verify whether admincp.php and weixin_category functionality are enabled.
  • Check whether the admin interface is internet-facing or access-controlled.
  • Review application changelogs or vendor notes for a fix reference.
  • Document exposure status and remediation decision in the vulnerability register.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-10250 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.