Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-58894
HistoryJun 27, 2022 - 12:00 a.m.

74cms Cross-Site Scripting Vulnerability (CNVD-2022-58894)

2022-06-2700:00:00
China National Vulnerability Database
www.cnvd.org.cn
14
php
mysql
online recruitment system
china xunyi technology co
cross-site scripting
user-supplied data
output data validation
/index/notice/show
javascript code

EPSS

0.001

Percentile

34.0%

74cms is a PHP and MySQL-based online recruitment system from China Xunyi Technology Co. 74cmsSE version v3.5.1 contains a cross-site scripting vulnerability, which originates from the lack of user-supplied data and output data validation filtering in /index/notice/show. An attacker could exploit this vulnerability to execute JavaScript code on the client side.

EPSS

0.001

Percentile

34.0%

Related for CNVD-2022-58894