PT-2026-27434 · Icms · Icms

Wang Yiru

+1

·

Published

2026-03-24

·

Updated

2026-03-24

·

CVE-2026-30661

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions iCMS version 8.0.0
Description The iCMS software contains a Cross-Site Scripting (XSS) issue in the User Management component. The issue is located within the index.html file and allows remote attackers to execute arbitrary web script or HTML. The attack vector involves the regip or loginip parameters.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, sanitize the regip and loginip parameters before processing them.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-30661

Affected Products

Icms