CVE-2019-9570: XSS
Published Mar 5, 2019
·Updated
An issue was discovered in YzmCMS 5.2.0. It has XSS via the bottom text field to the admin/systemmanage/save.html URI, related to the sitecode parameter.
Affected Software
1 affected component
YzmCMS YzmCMS=5.2.0
Event History
Mar 5, 2019
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-9570?
CVE-2019-9570 has a medium severity due to the potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2019-9570?
To fix CVE-2019-9570, ensure you validate and sanitize input from the site_code parameter to prevent XSS.
3
Which versions are affected by CVE-2019-9570?
CVE-2019-9570 affects YzmCMS version 5.2.0.
4
Can CVE-2019-9570 be exploited remotely?
Yes, CVE-2019-9570 can be exploited remotely if an attacker submits malicious input to the vulnerable URI.
5
What components of YzmCMS does CVE-2019-9570 impact?
CVE-2019-9570 impacts the admin/system_manage/save.html functionality in YzmCMS.