PT-2017-13676 · Genix · Genixcms

Published

2017-09-27

·

Updated

2022-05-17

·

CVE-2017-14762

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GeniXCMS version 1.1.4
Description The issue is related to a Cross-Site Scripting (XSS) problem. Specifically, the /inc/lib/Control/Backend/menus.control.php endpoint is vulnerable to XSS via the id parameter. This means an attacker could potentially inject malicious scripts into the website, affecting users who interact with the vulnerable page.
Recommendations For GeniXCMS version 1.1.4, as a temporary workaround, consider restricting access to the /inc/lib/Control/Backend/menus.control.php endpoint or avoid using the id parameter in this context until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-14762
GHSA-JGC6-JR94-H442

Affected Products

Genixcms