Stored XSS in YzmCMS 5.6 Allows Remote File Upload by Attackers
CVE-2020-23370
5.4MEDIUM
Summary
In YzmCMS version 5.6, a stored XSS vulnerability allows attackers to exploit the system via the 'action' parameter in the common/static/plugin/ueditor/1.4.3.3/php/controller.php file. This flaw facilitates the upload of malicious SWF files, potentially injecting harmful scripts or HTML code. When successfully executed, the attack could lead to unauthorized control and manipulation of web content, resulting in severe implications for user data and site integrity.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved