Stored Cross-Site Scripting in EyouCMS by Weng Xianhu
CVE-2023-48882
4.8MEDIUM
What is CVE-2023-48882?
The stored cross-site scripting vulnerability in EyouCMS version 1.6.4-UTF8-SP1 enables attackers to inject malicious web scripts or HTML. The exploit takes place via a specially crafted payload inserted into the Document Properties field, accessed through the administrative login section. This can lead to unauthorized script execution, compromising the integrity of the web application and possibly allowing attackers to manipulate user sessions or redirect users to malicious sites.