Stored XSS Vulnerability in EasyCMS by TeamEasy
CVE-2018-10527
5.4MEDIUM
What is CVE-2018-10527?
EasyCMS version 1.3 is susceptible to a Stored XSS vulnerability. This issue arises when users post articles, allowing an attacker to inject malicious scripts through four fields: title, keyword, abstract, and content. When these fields are rendered on the website, any scripts injected will execute in the browser of users viewing the affected content, potentially leading to unauthorized actions or data compromise.
