Stored XSS in YzmCMS 5.6 Allows Remote File Upload by Attackers
CVE-2020-23370

5.4MEDIUM

Key Information:

Vendor
Yzmcms
Status
Vendor
CVE Published:
10 May 2021

Summary

In YzmCMS version 5.6, a stored XSS vulnerability allows attackers to exploit the system via the 'action' parameter in the common/static/plugin/ueditor/1.4.3.3/php/controller.php file. This flaw facilitates the upload of malicious SWF files, potentially injecting harmful scripts or HTML code. When successfully executed, the attack could lead to unauthorized control and manipulation of web content, resulting in severe implications for user data and site integrity.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.