Stored Cross-Site Scripting Vulnerability in PowerCMS by PowerCMS Inc.
CVE-2023-49117
5.4MEDIUM
What is CVE-2023-49117?
PowerCMS, developed by PowerCMS Inc., exhibits a stored cross-site scripting vulnerability affecting multiple series, including the unsupported 3 Series. This vulnerability allows attackers to inject arbitrary scripts, which, if executed, can compromise the security of users' sessions in their web browsers. This can lead to unauthorized actions being taken on behalf of legitimate users, posing significant risks to the integrity of user data and overall application security.
Affected Version(s)
PowerCMS (PowerCMS 4 Series) 4.54 and earlier
PowerCMS (PowerCMS 5 Series) 5.24 and earlier
PowerCMS (PowerCMS 6 Series) 6.31 and earlier
