PT-2024-38834 · Classcms · Classcms
Acmglz
·
Published
2024-08-24
·
Updated
2024-09-18
·
CVE-2024-8145
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
ClassCMS version 4.8
Description:
A vulnerability has been found in ClassCMS, affecting some unknown functionality of the file /index.php/admin of the component Article Handler. The manipulation of the
Title argument leads to basic cross-site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.Recommendations:
For ClassCMS version 4.8, upgrade to version 4.9 to mitigate risks. As a temporary workaround, consider restricting access to the
/index.php/admin endpoint and the Title argument in the Article Handler component until the issue is resolved. Monitor for updates and apply patches as they become available.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Classcms