Eyoucms · Eyoucms · CVE-2023-34657
**Name of the Vulnerable Software and Affected Versions**
Eyoucms version 1.6.2
**Description**
A stored cross-site scripting (XSS) issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the `web recordnum` parameter. This enables attackers to potentially manipulate the website's behavior or steal user data.
**Recommendations**
For Eyoucms version 1.6.2, consider restricting access to the `web recordnum` parameter to minimize the risk of exploitation. As a temporary workaround, avoid using the `web recordnum` parameter in sensitive operations until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.