Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-97732
HistoryDec 13, 2023 - 12:00 a.m.

JFinalCMS Cross-Site Scripting Vulnerability (CNVD-2023-9773206)

2023-12-1300:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
jfinalcms
cross-site scripting
vulnerability
model management
web script
html
cnvd-2023-9773206

AI Score

6.6

Confidence

High

EPSS

0

Percentile

14.0%

JFinalCMS is a content management system. JFinalCMS suffers from a cross-site scripting vulnerability that stems from a lack of effective filtering and escaping of user-supplied data in the model management department, which can be exploited by an attacker to execute arbitrary Web script or HTML by injecting a carefully crafted payload.

AI Score

6.6

Confidence

High

EPSS

0

Percentile

14.0%