vendor:
Schlix CMS
by:
Emircan Baş
8.8
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: Schlix CMS
Affected Version From: 2.2.6-6
Affected Version To: 2.2.6-6
Patch Exists: YES
Related CWE: N/A
CPE: a:schlix:schlix_cms
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows & WampServer
2021
Schlix CMS 2.2.6-6 – ‘title’ Persistent Cross-Site Scripting (Authenticated)
Schlix CMS version 2.2.6-6 is vulnerable to a persistent cross-site scripting vulnerability. An authenticated user can inject malicious JavaScript code into the 'title' field of a contact category. This code will be executed when a user visits the page of the created category. The vulnerable code is located in the '/admin/app/contact' directory.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of Schlix CMS.