Stored Cross-Site Scripting Vulnerability in Feehi CMS Role Management Module
CVE-2026-31352

5.4MEDIUM

Key Information:

Vendor

Feehi

Status
Vendor
CVE Published:
6 April 2026

What is CVE-2026-31352?

An authenticated stored cross-site scripting (XSS) vulnerability exists in the Role Management module of Feehi CMS v2.1.1. This allows attackers to inject malicious scripts or HTML through crafted payloads in the Role Name parameter, potentially compromising the integrity of the application and its users. It can lead to various attacks, including session hijacking and data exfiltration, highlighting the importance of securing input fields against XSS.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.