Linzhaoguan · Linzhaoguan Pb-Cms · CVE-2024-10478
**Name of the Vulnerable Software and Affected Versions**
LinZhaoguan pb-cms versions up to 2.0.1
**Description**
A problematic issue has been found in the Edit Article Handler component, affecting the processing of the file "/admin#article/edit?id=2". This leads to cross-site scripting, and the attack can be initiated remotely. The issue has been publicly disclosed and may be exploited.
**Recommendations**
For versions up to 2.0.1, as a temporary workaround, consider restricting access to the "/admin#article/edit?id=2" endpoint until a patch is available. Avoid using the `id` parameter in the affected endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.