Cross-Site Scripting Vulnerability in light0011 CMS Chapter Content Output
CVE-2026-85382
Key Information:
Badges
What is CVE-2026-85382?
A vulnerability has been identified in the light0011 CMS specifically within the Chapter Content Output component. The issue lies in the function htmlspecialchars_decode located in the file App/Home/View/Default/Chapter/oneChapter.tpl. This flaw allows an attacker to manipulate the argument content, potentially leading to cross-site scripting (XSS) attacks. The remote exploitation of this vulnerability is feasible, as the exploit has already been made public. Although the project was notified about the vulnerability early through an issue report, no response has been documented yet. Given that light0011 CMS follows a rolling release model, specific version details for affected or updated releases are unavailable.
Affected Version(s)
cms c774dce31c6df0055568a8d5c53d964d99be199d
cms f72cf46f601efb2a0618c3814cc2f61380b38930
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
