vendor:
Textpattern CMS
by:
tmrswrr
7.5
CVSS
HIGH
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: Textpattern CMS
Affected Version From: 4.8.2008
Affected Version To: 4.8.2008
Patch Exists: NO
Related CWE:
CPE: a:textpattern:textpattern:4.8.8
Platforms Tested:
2023
Textpattern CMS v4.8.8 – Stored Cross-Site Scripting (XSS) (Authenticated)
The Textpattern CMS v4.8.8 is vulnerable to stored cross-site scripting (XSS) attacks. An authenticated user can inject malicious JavaScript code into the Excerpt field of the Articles section in the admin page. When this payload is executed, it will trigger an alert displaying the user's cookie information.
Mitigation:
To mitigate this vulnerability, users are advised to update to a patched version of Textpattern CMS.