Cross-Site Scripting Vulnerability in Typecho by Typecho Team
CVE-2017-16230
5.4MEDIUM
What is CVE-2017-16230?
A Cross-Site Scripting (XSS) vulnerability exists in Typecho versions up to 1.1, allowing authenticated users to exploit the admin interface. By crafting a malicious article, an attacker can inject harmful scripts into the content. This payload is executed when users access the backend through the index.php/action/contents-post-edit endpoint, potentially compromising the security of the web application and its users.
