PT-2024-39284 · Autocms · Autocms
Jiashenghe
·
Published
2024-09-14
·
Updated
2024-09-20
·
CVE-2024-8866
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
AutoCMS version 5.4
Description:
A vulnerability was found in AutoCMS, affecting an unknown part of the file /admin/robot.php. The manipulation of the
sidebar argument leads to cross-site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This issue can compromise admin access and lead to data theft.Recommendations:
For AutoCMS version 5.4, patch immediately and validate user input to prevent exploitation. As a temporary workaround, consider restricting access to the
/admin/robot.php endpoint or disabling the manipulation of the sidebar argument until a patch is available.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Autocms