Reflected Cross-Site Scripting Vulnerability in EyouCms by Eyou
CVE-2023-41597
6.1MEDIUM
Summary
EyouCms version 1.6.2 is vulnerable to a reflected cross-site scripting (XSS) attack through the /admin/twitter.php?active_t component. This vulnerability allows attackers to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking, redirecting users to malicious sites, or stealing sensitive information. Website administrators and users are urged to apply security patches and update their installations to mitigate the risks associated with this vulnerability.
References
EPSS Score
10% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved