Stored XSS in YzmCMS 5.6 Allows Remote File Upload by Attackers
CVE-2020-23370
5.4MEDIUM
What is CVE-2020-23370?
In YzmCMS version 5.6, a stored XSS vulnerability allows attackers to exploit the system via the 'action' parameter in the common/static/plugin/ueditor/1.4.3.3/php/controller.php file. This flaw facilitates the upload of malicious SWF files, potentially injecting harmful scripts or HTML code. When successfully executed, the attack could lead to unauthorized control and manipulation of web content, resulting in severe implications for user data and site integrity.