First published: Fri Feb 17 2023(Updated: )
A cross-site scripting (XSS) vulnerability in UJCMS v4.1.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter under the Add New Articles function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
UJCMS Jspxcms | >=4.1.3<5.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-24369 is classified as medium with a CVSS score of 6.1.
The XSS vulnerability in UJCMS v4.1.3 occurs by injecting a crafted payload into the URL parameter under the Add New Articles function, allowing attackers to execute arbitrary web scripts or HTML.
Yes, attackers can execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter under the Add New Articles function in UJCMS v4.1.3.