Eyoucms · Eyoucms · CVE-2022-45280
**Name of the Vulnerable Software and Affected Versions**
EyouCMS version 1.6.0
**Description**
A cross-site scripting (XSS) issue exists in the `Url` parameter of the "/login.php" API endpoint, allowing attackers to execute arbitrary web scripts or HTML via a crafted payload.
**Recommendations**
For EyouCMS version 1.6.0, consider disabling the `/login.php` endpoint until a patch is available, or restrict access to this endpoint to minimize the risk of exploitation. Avoid using the `Url` parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.