Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Splint3Rsec

#47157of 53,622
5.4Total CVSS
Vulnerabilities · 1
PT-2021-21305
5.4
2021-08-03
Cmsuno · Cmsuno · CVE-2021-36654
**Name of the Vulnerable Software and Affected Versions** CMSuno version 1.7 **Description** The issue concerns an authenticated stored cross-site scripting vulnerability. It occurs when modifying the `filename` parameter, specifically the `tgo` variable, while updating the theme. **Recommendations** For CMSuno version 1.7, avoid using the `tgo` variable in the filename parameter when updating the theme until a fix is available. Consider restricting access to theme updates to minimize the risk of exploitation.