← back
CVE-2024-12503

ClassCMS Model Management Page admin cross site scripting

CVSS 5.1 MEDIUMEPSS 0.5%CWE-79CWE-94
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.1EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
12 Dec 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component Model Management Page. The manipulation of the argument URL leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
n/a · ClassCMS