CVE-2026-31352: XSS
An authenticated stored cross-site scripting (XSS) vulnerability in the Role Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Role Name parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31352?
CVE-2026-31352 is classified as a moderate severity vulnerability due to its potential for authenticated stored cross-site scripting (XSS) attacks.
How do I fix CVE-2026-31352?
The recommended fix for CVE-2026-31352 is to sanitize and validate the Role Name input to prevent the injection of malicious scripts.
What versions of Feehi CMS are affected by CVE-2026-31352?
CVE-2026-31352 affects Feehi CMS version 2.1.1.
Can CVE-2026-31352 be exploited remotely?
No, CVE-2026-31352 requires authenticated access to exploit the stored XSS vulnerability.
What are the potential impacts of CVE-2026-31352?
Exploitation of CVE-2026-31352 could lead to unauthorized execution of malicious scripts in a user's browser when accessing the application.