First published: Fri May 19 2023(Updated: )
jizhicms v2.4.6 is vulnerable to Cross Site Scripting (XSS). The content of the article published in the front end is only filtered in the front end, without being filtered in the background, which allows attackers to publish an article containing malicious JavaScript scripts by modifying the request package.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jizhicms Jizhicms | =2.4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-31862.
The severity of CVE-2023-31862 is medium (5.4).
The affected software version of CVE-2023-31862 is Jizhicms v2.4.6.
The Common Weakness Enumeration (CWE) ID for this vulnerability is CWE-79.
To fix CVE-2023-31862, you should update Jizhicms to a version that has addressed the Cross Site Scripting (XSS) vulnerability.