CVE-2026-7429: SSCMS v7.4.0 Reflected Cross-Site Scripting via STL Processing
SSCMS v7.4.0 contains a reflected cross-site scripting vulnerability in the STL processing endpoint that allows attackers to execute arbitrary JavaScript by crafting malicious STL template payloads that are decrypted and returned without proper sanitization. Attackers can exploit improper output encoding in the /api/stl/actions/dynamic endpoint to inject executable JavaScript into JSON responses, leading to session hijacking, phishing attacks, and unauthorized actions performed on behalf of users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7429?
The severity of CVE-2026-7429 is considered high due to its potential for executing arbitrary JavaScript.
How do I fix CVE-2026-7429?
To fix CVE-2026-7429, update SSCMS to the latest version that addresses the reflected cross-site scripting vulnerability.
Who is affected by CVE-2026-7429?
CVE-2026-7429 affects users of SSCMS version 7.4.0.
What type of vulnerability is CVE-2026-7429?
CVE-2026-7429 is a reflected cross-site scripting (XSS) vulnerability.
How can attackers exploit CVE-2026-7429?
Attackers can exploit CVE-2026-7429 by sending crafted STL template payloads to the vulnerable endpoint.