CVE-2022-23889

MEDIUM

YzmCMS v6.3 - Uncontrolled Recursion via Comment Function

Title source: llm
STIX 2.1

Description

The comment function in YzmCMS v6.3 was discovered as being able to be operated concurrently, allowing attackers to create an unusually large number of comments.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/yzmcms/yzmcms/issues/61

Scores

CVSS v3 5.3
EPSS 0.0106
EPSS Percentile 60.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-674
Status published
Products (1)
yzmcms/yzmcms 6.3
Published Jan 28, 2022
Tracked Since Feb 18, 2026