github.com
https://github.com/ponyma233/YzmCMS/blob/master/YzmCMS_3.6_bug.md CVE-2018-7653
MEDIUMNuclei
YzmCMS 3.6 - Cross-Site Scripting
Record summary
CVE-2018-7653 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Proofs of concept
1Catalogued exploits
ExploitDBYzmCMS 3.6 - Cross-Site ScriptingExploitDB exploitby zzwNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMYzmCMS v3.6 - Cross-Site ScriptingCVSS 6.1
In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.
Impact
Attackers can execute arbitrary JavaScript in victims' browsers, potentially stealing session cookies, credentials, or performing actions on behalf of authenticated users.
Remediation
To mitigate this vulnerability, it is recommended to implement proper input validation and sanitization techniques to prevent the execution of malicious scripts.
WeaknessesCWE-79
Authorsritikchaddha
Template tagscvecve2018packetstormyzmcmscmsxssvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:yzmcms:yzmcms:3.6:*:*:*:*:*:*:*
Shodan: title:"YzmCMS"
Shodan: http.title:"yzmcms"
FOFA: title="YzmCMS"
FOFA: title="yzmcms"
Google: intitle:"yzmcms"
https://packetstormsecurity.com/files/147065/YzmCMS-3.6-Cross-Site-Scripting.html https://nvd.nist.gov/vuln/detail/CVE-2018-7653 https://github.com/ponyma233/YzmCMS/blob/master/YzmCMS_3.6_bug.md https://github.com/anquanquantao/iwantacve https://github.com/5ecurity/CVE-List
Source: ProjectDiscovery
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-7653 packetstormsecurity.com
https://packetstormsecurity.com/files/147065/YzmCMS-3.6-Cross-Site-Scripting.html 44405exploit
https://www.exploit-db.com/exploits/44405