Reflected Cross-Site Scripting Vulnerability in EyouCms by Eyou
CVE-2023-41597

6.1MEDIUM

Key Information:

Vendor
Eyoucms
Status
Vendor
CVE Published:
15 November 2023

Summary

EyouCms version 1.6.2 is vulnerable to a reflected cross-site scripting (XSS) attack through the /admin/twitter.php?active_t component. This vulnerability allows attackers to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking, redirecting users to malicious sites, or stealing sensitive information. Website administrators and users are urged to apply security patches and update their installations to mitigate the risks associated with this vulnerability.

References

EPSS Score

10% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-41597 : Reflected Cross-Site Scripting Vulnerability in EyouCms by Eyou | SecurityVulnerability.io