Storage Type XSS Vulnerability in EyouCMS by Weng Xianhu
CVE-2023-36093

5.4MEDIUM

Key Information:

Vendor

Eyoucms

Status
Vendor
CVE Published:
22 June 2023

What is CVE-2023-36093?

A storage type cross site scripting (XSS) vulnerability has been identified in the filing number section of the Basic Information tab on the backend management page of EyouCMS version 1.6.3. This flaw could allow attackers to inject malicious scripts, potentially compromising user sessions and sensitive data by exploiting unvalidated input fields.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-36093 : Storage Type XSS Vulnerability in EyouCMS by Weng Xianhu