Cross-Site Scripting Vulnerability in WUZHI CMS Affects Multiple Versions
CVE-2019-9107

6.1MEDIUM

Key Information:

Vendor

Wuzhicms

Status
Vendor
CVE Published:
25 February 2019

What is CVE-2019-9107?

A Cross-Site Scripting vulnerability exists in WUZHI CMS 4.1.0 that allows an attacker to inject malicious scripts through unsanitized input in the 'imgurl' parameter. This can occur via accessing the route index.php?m=attachment&f=imagecut&v=init&imgurl=[XSS], which may lead to unauthorized access and data exposure. Proper input validation measures are critical to mitigate this risk and enhance the security posture of web applications using this CMS.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.