vendor:
WBCE CMS
by:
Mirabbas Agalarov
7.5
CVSS
HIGH
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: WBCE CMS
Affected Version From: 1.6.2001
Affected Version To: 1.6.2001
Patch Exists: NO
Related CWE:
CPE: a:wbce_cms_project:wbce_cms:1.6.1
Platforms Tested: Linux
2023
WBCE CMS 1.6.1 – Multiple Stored Cross-Site Scripting (XSS)
The WBCE CMS version 1.6.1 is vulnerable to multiple stored cross-site scripting (XSS) attacks. An attacker can upload a malicious SVG file containing a script that will be executed when viewed by an authenticated user with administrative privileges. This can lead to the execution of arbitrary code or the theft of sensitive information.
Mitigation:
To mitigate this vulnerability, it is recommended to update to the latest version of WBCE CMS or apply the vendor-provided patch when available. Additionally, users should avoid uploading or opening files from untrusted sources.