CVE-2013-20006

HIGH

Qool CMS Multiple Persistent Cross-Site Scripting Vulnerabilities

Title source: cna
STIX 2.1

Description

Qool CMS contains multiple persistent cross-site scripting vulnerabilities in several administrative scripts where POST parameters are not properly sanitized before being stored and returned to users. Attackers can inject malicious JavaScript code through parameters like 'title', 'name', 'email', 'username', 'link', and 'task' in endpoints such as addnewtype, addnewdatafield, addmenu, addusergroup, addnewuserfield, adduser, addgeneraldata, and addcontentitem to execute arbitrary scripts in administrator browsers.

Exploits (1)

exploitdb WORKING POC VERIFIED
by LiquidWorm · textwebappsphp
https://www.exploit-db.com/exploits/24627

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-24627
https://www.exploit-db.com/exploits/24627
Vendor Advisory vendor-advisory
Vulnerability Advisory
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2013-5133.php
Third Party Advisory third-party-advisory
VulnCheck Advisory: Qool CMS Multiple Persistent Cross-Site Scripting Vulnerabilities
https://www.vulncheck.com/advisories/qool-cms-multiple-persistent-cross-site-scripting-vulnerabilities

Scores

CVSS v3 7.5
EPSS 0.0007
EPSS Percentile 20.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
Qool/Qool CMS 2.0
Published Mar 16, 2026
Tracked Since Mar 16, 2026