Record summary

CVE-2018-7653 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBYzmCMS 3.6 - Cross-Site ScriptingExploitDB exploitby zzwNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMYzmCMS v3.6 - Cross-Site ScriptingCVSS 6.1

In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.

Impact

Attackers can execute arbitrary JavaScript in victims' browsers, potentially stealing session cookies, credentials, or performing actions on behalf of authenticated users.

Remediation

To mitigate this vulnerability, it is recommended to implement proper input validation and sanitization techniques to prevent the execution of malicious scripts.

WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2018packetstormyzmcmscmsxssvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:yzmcms:yzmcms:3.6:*:*:*:*:*:*:*
Shodan: title:"YzmCMS"
Shodan: http.title:"yzmcms"
FOFA: title="YzmCMS"
FOFA: title="yzmcms"
Google: intitle:"yzmcms"

Source: ProjectDiscovery

References

4