Cross-Site Scripting Vulnerability in InstantSoft icms2 Software
CVE-2026-108566
5.1MEDIUM
What is CVE-2026-108566?
A vulnerability exists in InstantSoft icms2 versions up to 2.18.2, specifically affecting the Private Message Handler functionality. This security flaw allows for potential remote exploitation due to improper validation of the nickname argument within the index function of the templates/default/controllers/messages/index.tpl.php file. Attackers are able to inject malicious scripts, threatening the integrity and confidentiality of user data. It is crucial for users and administrators to apply the recommended patch (3a1ec8fcb073a46d06a2ab83bc2bf68225834281) to mitigate any risks associated with this vulnerability.
Affected Version(s)
icms2 2.18.0
icms2 2.18.1
icms2 2.18.2
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
EVIL0RD (VulDB User)
VulDB Vulnerability Moderation Team
