Yzmcms · Yzmcms · CVE-2024-24291
**Name of the Vulnerable Software and Affected Versions**
yzmcms version 7.0
**Description**
An issue in the component /member/index/login of yzmcms allows attackers to direct users to malicious sites via a crafted URL.
**Recommendations**
For yzmcms version 7.0, consider restricting access to the /member/index/login component until a patch is available. As a temporary workaround, avoid using crafted URLs that could redirect users to malicious sites. At the moment, there is no information about a newer version that contains a fix for this issue.