PT-2024-28378 · Yzmcms · Yzmcms

1Ang

·

Published

2024-07-05

·

Updated

2025-06-13

·

CVE-2024-39174

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions yzmcms version 7.1
Description A cross-site scripting (XSS) vulnerability in the Publish Article function allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a published article.
Recommendations For yzmcms version 7.1, consider disabling the Publish Article function until a patch is available to prevent exploitation of the XSS vulnerability. Restrict access to published articles to minimize the risk of arbitrary web script execution.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-39174

Affected Products

Yzmcms