splint3rsec

1 exploit Active since Aug 2021
CVE-2021-36654 EXPLOITDB MEDIUM text WRITEUP
CMSuno 1.7 - Authenticated Stored Cross-Site Scripting via Theme Filename Parameter
CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while updating the theme.
CVSS 5.4