Cross-Site Scripting Vulnerability in WUZHI CMS Affects Multiple Versions
CVE-2019-9107
6.1MEDIUM
What is CVE-2019-9107?
A Cross-Site Scripting vulnerability exists in WUZHI CMS 4.1.0 that allows an attacker to inject malicious scripts through unsanitized input in the 'imgurl' parameter. This can occur via accessing the route index.php?m=attachment&f=imagecut&v=init&imgurl=[XSS], which may lead to unauthorized access and data exposure. Proper input validation measures are critical to mitigate this risk and enhance the security posture of web applications using this CMS.