Stored Cross-Site Scripting Vulnerability in Eyoucms by Weng Xianhu
CVE-2023-34657

4.8MEDIUM

Key Information:

Vendor
Eyoucms
Status
Vendor
CVE Published:
19 June 2023

Summary

Eyoucms version 1.6.2 is vulnerable to a stored cross-site scripting (XSS) attack, allowing attackers to inject and execute malicious web scripts or HTML code. This exploit occurs via the manipulation of the web_recordnum parameter, which can lead to significant security risks, including data theft and unauthorized access. It's essential for users of this version to implement security measures and update to mitigate the threat.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.