PT-2026-33755 · Yifang · Cms

Shiyifei

·

Published

2026-04-20

·

Updated

2026-04-20

·

CVE-2026-6633

CVSS v3.1

3.5

Low

AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
A security flaw has been discovered in Yifang CMS up to 2.0.5. The impacted element is the function store of the file plugins/yifang backend account/logic/admin/L rbac admin.php of the component Extended Management Module. The manipulation of the argument Account results in cross site scripting. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-6633

Affected Products

Cms