Cross-Site Scripting Vulnerability in Yourls Admin Panel
CVE-2014-8488
Currently unrated
What is CVE-2014-8488?
A cross-site scripting (XSS) vulnerability exists in the administrator panel of Yourls version 1.7. This flaw allows remote attackers to inject arbitrary web scripts or HTML through URLs processed by the Shorten functionality. Successful exploitation can lead to unauthorized execution of scripts in the context of the logged-in administrator, allowing attackers to manipulate content or compromise the security of the application. Administrators are advised to apply security patches promptly to mitigate the risk associated with this vulnerability.
