PT-2026-36171 · Siteserver · Sscms

Hss94531

·

Published

2026-04-30

·

Updated

2026-04-30

·

CVE-2026-7429

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
SSCMS v7.4.0 contains a reflected cross-site scripting vulnerability in the STL processing endpoint that allows attackers to execute arbitrary JavaScript by crafting malicious STL template payloads that are decrypted and returned without proper sanitization. Attackers can exploit improper output encoding in the /api/stl/actions/dynamic endpoint to inject executable JavaScript into JSON responses, leading to session hijacking, phishing attacks, and unauthorized actions performed on behalf of users.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-7429

Affected Products

Sscms