Stored Cross-Site Scripting in EyouCMS by Weng Xianhu
CVE-2023-48882
4.8MEDIUM
Summary
The stored cross-site scripting vulnerability in EyouCMS version 1.6.4-UTF8-SP1 enables attackers to inject malicious web scripts or HTML. The exploit takes place via a specially crafted payload inserted into the Document Properties field, accessed through the administrative login section. This can lead to unauthorized script execution, compromising the integrity of the web application and possibly allowing attackers to manipulate user sessions or redirect users to malicious sites.
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved