vendor:
EyouCMS
by:
China Banking and Insurance Information Technology Management Co.,Ltd.
7.5
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: EyouCMS
Affected Version From: EyouCMS V1.4.6
Affected Version To: EyouCMS V1.4.6
Patch Exists: NO
Related CWE: N/A
CPE: a:eyoucms:eyoucms:1.4.6
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2020
EyouCMS 1.4.6 – Persistent Cross-Site Scripting
EyouCMS V1.4.6 is vulnerable to Persistent Cross-Site Scripting. An attacker can send a malicious POST request to the vulnerable application with a crafted payload in the 'addonFieldExt[content]' parameter. This will result in a persistent XSS vulnerability which can be used to steal user's cookies and other sensitive information.
Mitigation:
The vendor should patch the application to prevent the exploitation of this vulnerability.