Cross-Site Scripting Vulnerability in Qibo CMS from Guangzhou Qibo Network Technology Co., Ltd.
CVE-2026-6648
Key Information:
Badges
What is CVE-2026-6648?
A security vulnerability has been discovered in the Internal Message Module of Qibo CMS 1.0, which allows for potential cross-site scripting (XSS) attacks. This vulnerability enables remote attackers to execute arbitrary scripts in the context of a user's session. The exploit has been publicly disclosed, highlighting the urgency for users to implement security measures. Despite prior notification, the vendor has not responded to the issue, leaving users susceptible to potential exploitation.
Affected Version(s)
CMS 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
