Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Opopo3321

#43026of 53,632
6.1Total CVSS
Vulnerabilities · 1
PT-2023-31484
6.1
2023-09-16
Ucms · Ucms · CVE-2023-5015
**Name of the Vulnerable Software and Affected Versions** UCMS version 1.4.7 **Description** A problematic issue has been identified, allowing for cross-site scripting through the manipulation of the `strdefault` argument in an unknown function of the file "ajax.php?do=strarraylist". This can be exploited remotely. **Recommendations** For UCMS version 1.4.7, consider restricting access to the "ajax.php?do=strarraylist" endpoint until a fix is available. As a temporary workaround, avoid using the `strdefault` argument in this endpoint to minimize the risk of exploitation.