PT-2024-39284 · Autocms · Autocms

Jiashenghe

·

Published

2024-09-14

·

Updated

2024-09-20

·

CVE-2024-8866

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: AutoCMS version 5.4
Description: A vulnerability was found in AutoCMS, affecting an unknown part of the file /admin/robot.php. The manipulation of the sidebar argument leads to cross-site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This issue can compromise admin access and lead to data theft.
Recommendations: For AutoCMS version 5.4, patch immediately and validate user input to prevent exploitation. As a temporary workaround, consider restricting access to the /admin/robot.php endpoint or disabling the manipulation of the sidebar argument until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-8866

Affected Products

Autocms