vendor:
CSZ CMS
by:
Daniel González
6.1
CVSS
MEDIUM
Stored Cross-Site Scripting
79
CWE
Product Name: CSZ CMS
Affected Version From: 1.3.2000
Affected Version To: 1.3.2000
Patch Exists: NO
Related CWE: CVE-2023-38910
CPE: a:csz_cms_project:csz_cms:1.3.0
Platforms Tested: CSZ CMS 1.3.0
2023
CSZ CMS 1.3.0 – Stored Cross-Site Scripting (‘Photo URL’ and ‘YouTube URL’ )
CSZ CMS 1.3.0 is vulnerable to cross-site scripting (XSS), which allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered in the 'Carousel Wiget' section and choosing our carousel widget created above, in 'Photo URL' and 'YouTube URL' plugin.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize and validate user input before displaying it on the website. Additionally, regular security audits and updates should be performed to ensure the latest patches and security measures are in place.