Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-05632
HistoryJan 24, 2024 - 12:00 a.m.

Jspxcms Cross-Site Scripting Vulnerability (CNVD-2024-05632)

2024-01-2400:00:00
China National Vulnerability Database
www.cnvd.org.cn
13
jspxcms
cross-site scripting
vulnerability
web content management
cnvd-2024-05632

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

20.6%

Jspxcms is a scalable enterprise-class open source web content management system (CMS). Jspxcms version 10.2.0 cross-site scripting vulnerability , the vulnerability stems from the lack of effective user-supplied data filtering and escaping component Survey Label Handler , an attacker can exploit the vulnerability by injecting a well-designed payload to execute arbitrary Web script or HTML.

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

20.6%

Related for CNVD-2024-05632