CVE-2010-5318

SweetRice CMS <0.6.7.1 - XSS

Title source: llm
STIX 2.1

Description

The password-reset feature in as/index.php in SweetRice CMS before 0.6.7.1 allows remote attackers to modify the administrator's password by specifying the administrator's e-mail address in the email parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by High-Tech Bridge SA · textwebappsphp
https://www.exploit-db.com/exploits/15413

References (1)

Core 1
Core References

Scores

EPSS 0.0343
EPSS Percentile 87.5%

Details

CWE
CWE-255
Status published
Products (1)
basic-cms/sweetrice 0.6.7.1
Published Jan 03, 2015
Tracked Since Feb 18, 2026