Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Dililearngentop

#50208of 53,633
4.8Total CVSS
Vulnerabilities · 1
PT-2023-30997
4.8
2023-11-29
Eyoucms · Eyoucms · CVE-2023-48882
**Name of the Vulnerable Software and Affected Versions** EyouCMS version 1.6.4-UTF8-SP1 **Description** A stored cross-site scripting (XSS) issue allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Document Properties field at "/login.php m=admin&c=Index&a=changeTableVal& ajax=1&lang=cn". **Recommendations** For EyouCMS version 1.6.4-UTF8-SP1, consider disabling access to the "/login.php" endpoint with the specific parameters `m=admin`, `c=Index`, `a=changeTableVal`, ` ajax=1`, and `lang=cn` until a patch is available. Restrict the ability to inject payloads into the Document Properties field to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.