Cross-Site Scripting Vulnerability in SiberianCMS by Siberian.
CVE-2017-6906
6.1MEDIUM
What is CVE-2017-6906?
A significant cross-site scripting (XSS) vulnerability has been identified in SiberianCMS prior to version 4.10.0. This security flaw arises from inadequate filtering of user-supplied data passed to the 'SiberianCMS-master/errors/500.php' URL. By exploiting this issue, an attacker could inject and execute arbitrary HTML and script code within a user's browser, potentially compromising the security of the affected website and its users.