PT-2026-29444 · Gougucms · Gougucms

Thinhnee

+1

·

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2026-5249

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions gougucms version 4.08.18
Description A cross-site scripting issue exists in gougucms 4.08.18. The issue is located in an unknown function of the file gougucms-masterappadminviewuserrecord.html within the Record Endpoint component. Manipulation of the value.content argument can lead to cross-site scripting. The attack can be initiated remotely, and the exploit has been publicly released. The vendor was contacted but did not respond.
Recommendations For gougucms version 4.08.18, address the cross-site scripting issue by sanitizing the value.content argument in the gougucms-masterappadminviewuserrecord.html file of the Record Endpoint component.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-5249

Affected Products

Gougucms