vendor:
CMSuno
by:
splint3rsec
5.4
CVSS
MEDIUM
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: CMSuno
Affected Version From: CMSuno 1.0
Affected Version To: CMSuno 1.7
Patch Exists: YES
Related CWE: CVE-2021-36654
CPE: a:boiteasite:cmsuno:1.7
Platforms Tested:
2021
CMSuno 1.7 – ‘tgo’ Stored Cross-Site Scripting (XSS) (Authenticated)
CMSuno version 1.7 and prior is vulnerable to a stored cross-site scripting. The attacker must be authenticated to exploit the vulnerability. The payload injection is done while updating the template's image filename, vulnerable parameter is *tgo*.
Mitigation:
Upgrade to the latest version of CMSuno.