CVE-2024-35110: XSS
Published May 17, 2024
·Updated
A reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.class.php: when logged-in users access a malicious link, their cookies can be captured by an attacker.
Affected Software
2 affected components
YzmCMS YzmCMS
YzmCMS YzmCMS=7.1
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 17, 2024
CVE Published
via NVD·08:15 AM
Aug 2, 2024
Data Sourced
via MITRE·03:10 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-35110?
CVE-2024-35110 is classified as a high severity reflected XSS vulnerability.
2
How do I fix CVE-2024-35110?
To mitigate CVE-2024-35110, ensure that user inputs are properly sanitized and implement content security policies.
3
Who is affected by CVE-2024-35110?
CVE-2024-35110 affects users of YzmCMS version 7.1.
4
What can an attacker do with CVE-2024-35110?
An attacker can capture cookies from authenticated users visiting a malicious link due to CVE-2024-35110.
5
Is there a patch available for CVE-2024-35110?
Check the official YzmCMS repository for any updates or patches related to CVE-2024-35110.