Security readout for executives and security teams
Plain-English summary
CVE-2018-10250 is a reported cross-site scripting issue in iCMS V7.0.8. A value submitted through the WeChat classified management keyword search could run script in a user’s browser. Business impact depends on who can reach that admin function; if exposed to administrators, it could support session abuse or misleading admin actions.
Executive priority
Prioritize confirmation over emergency response. The issue affects an administrative search path and has no sourced active exploitation signal, but XSS in admin tooling can still create account and data integrity risk if the panel is exposed.
Technical view
The CVE description identifies XSS in the admincp.php keywords parameter during a weixin_category action, described as WeChat Classified Management keyword search. The source bundle provides no CVSS score, CWE, patch version, or detailed affected CPEs. Treat the named iCMS V7.0.8 path as the grounded exposure indicator.
Likely exposure
Likely exposure is limited to environments running iCMS V7.0.8 where the affected admincp.php WeChat category search function is present and reachable. Public exposure is not established by the sources. Confirm whether admin access is internet-facing, restricted to trusted networks, or unused.
Exploitation context
The source bundle reports the vulnerability but does not show CISA KEV inclusion or active exploitation evidence. The public GitHub issue is the only referenced disclosure source. Evidence is sufficient to identify the vulnerable feature, but incomplete for severity, exploit prevalence, or vendor remediation status.
Researcher notes
The record is sparse: no CVSS, CWE, CPE, or official remediation metadata appears in the supplied bundle. Use the CVE description and GitHub issue as source anchors, and avoid broad product assumptions beyond iCMS V7.0.8 and the named admin action.
Mitigation direction
- Check the iCMS project issue and vendor guidance for fixed versions or official patches.
- Inventory and prioritize any iCMS V7.0.8 deployments.
- Restrict access to iCMS admin interfaces to trusted users and networks.
- Apply compensating browser and application controls where vendor fixes are unavailable.
- Review logs for suspicious admin keyword-search activity.
Validation and detection
- Confirm whether iCMS V7.0.8 is installed in production or staging.
- Verify whether admincp.php and weixin_category functionality are enabled.
- Check whether the admin interface is internet-facing or access-controlled.
- Review application changelogs or vendor notes for a fix reference.
- Document exposure status and remediation decision in the vulnerability register.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2018-10250 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/idreamsoft/iCMS/issues/22CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
