CVE-2023-52274: XSS
Published Jan 11, 2024
·Updated
member/index/register.html in YzmCMS 6.5 through 7.0 allows XSS via the Referer HTTP header.
Affected Software
1 affected component
YzmCMS YzmCMS>=6.5<=7.0
Event History
Jan 11, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-52274?
CVE-2023-52274 is classified as a medium severity vulnerability due to the potential for XSS attacks.
2
How do I fix CVE-2023-52274?
To fix CVE-2023-52274, update YzmCMS to version 7.1 or later, which addresses this XSS vulnerability.
3
What software versions are affected by CVE-2023-52274?
CVE-2023-52274 affects YzmCMS versions 6.5 through 7.0.
4
What type of vulnerability is CVE-2023-52274?
CVE-2023-52274 is an XSS (Cross-Site Scripting) vulnerability.
5
How can CVE-2023-52274 be exploited?
CVE-2023-52274 can be exploited by injecting malicious scripts through the Referer HTTP header.