Stored Cross-Site Scripting Vulnerability in eyoucms by Weng Xianhu
CVE-2023-37136
5.4MEDIUM
What is CVE-2023-37136?
A stored cross-site scripting vulnerability exists in the Basic Website Information module of eyoucms version 1.6.3. This vulnerability enables attackers to inject and execute arbitrary web scripts or HTML by leveraging a specially crafted payload. If exploited, this can lead to unauthorized actions, data theft, or defacement of web applications, emphasizing the critical need for timely patching and rigorous input validation.