vendor:
CSZ CMS
by:
Metin Yunus Kandemir
7.5
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: CSZ CMS
Affected Version From: 1.2.7
Affected Version To: 1.2.7
Patch Exists: NO
Related CWE: N/A
CPE: a:cszcms:csz_cms:1.2.7
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2020
CSZ CMS 1.2.7 – Persistent Cross-Site Scripting
Unauthorized user that has access private message can embed Javascript code to admin panel. Steps to reproduce: 1- Log in to member panel. 1- Change user-agent header as <script>alert(1)</script> 2- Send the private message to admin user. 3- When admin user logs in to Backend System Dashboard, an alert box pops up on screen.
Mitigation:
Ensure that user-agent header is properly sanitized and validated before being used in the application.