Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-09601
HistoryFeb 10, 2023 - 12:00 a.m.

Yzmcms Cross-Site Scripting Vulnerability (CNVD-2023-09601)

2023-02-1000:00:00
China National Vulnerability Database
www.cnvd.org.cn
12
yzmcms
cms
cross-site scripting

0.001 Low

EPSS

Percentile

23.3%

Yzmcms is an open source CMS (Content Management System) for Yzmcms individual developers. cross-site scripting vulnerability exists in Yzmcms version 6.1. A remote attacker can use the vulnerability to steal user cookies through the image clipping feature.

CPENameOperatorVersion
yzmcms yzmcmseq6.1

0.001 Low

EPSS

Percentile

23.3%

Related for CNVD-2023-09601