Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-03909
HistoryDec 12, 2021 - 12:00 a.m.

DouPHP Cross-Site Scripting Vulnerability (CNVD-2022-03909)

2021-12-1200:00:00
China National Vulnerability Database
www.cnvd.org.cn
7

0.001 Low

EPSS

Percentile

31.5%

DouPHP is a lightweight enterprise content management system (CMS) from China DouShell Network Technology, Inc. A cross-site scripting vulnerability exists in DouPHP, which stems from a lack of data validation filtering of user-supplied and output data in /admin/cloud.php. An attacker could exploit this vulnerability to execute JavaScript code on the client side.

CPENameOperatorVersion
douphp douphp veq1.6

0.001 Low

EPSS

Percentile

31.5%

Related for CNVD-2022-03909