vendor:
Kuicms Php EE
by:
China Banking and Insurance Information Technology Management Co.,Ltd.
7.5
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: Kuicms Php EE
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: Yes
Related CWE: N/A
CPE: a:kuicms:kuicms_php_ee
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2020
Kuicms Php EE 2.0 – Persistent Cross-Site Scripting
A persistent cross-site scripting vulnerability exists in Kuicms Php EE 2.0. An attacker can send a malicious POST request with a crafted payload to the vulnerable application in order to execute arbitrary HTML or JavaScript code in the context of the vulnerable application.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should upgrade to the latest version of Kuicms Php EE 2.0.