vendor:
CSZ CMS
by:
Daniel González
5.4
CVSS
MEDIUM
Stored Cross-Site Scripting
79
CWE
Product Name: CSZ CMS
Affected Version From: 1.3.2000
Affected Version To: 1.3.2000
Patch Exists: YES
Related CWE: CVE-2023-38911
CPE: a:csz_cms:csz_cms:1.3.0
Platforms Tested:
2023
CSZ CMS 1.3.0 – Stored Cross-Site Scripting (Plugin ‘Gallery’)
CSZ CMS 1.3.0 is affected by a cross-site scripting (XSS) feature that allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered in the 'Gallery' section and choosing our Gallery. previously created, in the 'YouTube URL' field, this input is affected by an XSS. It should be noted that previously when creating a gallery the "Name" field was vulnerable to XSS, but this was resolved in the current version 1.3.0, the vulnerability found affects the "YouTube URL" field within the created gallery.
Mitigation:
Update to the latest version of CSZ CMS to fix the vulnerability. Avoid using user input directly in the 'YouTube URL' field.