← voltar
CVE-2024-8145

ClassCMS Article admin cross site scripting

CVSS 5.1 MEDIUMEPSS 0.4%CWE-80
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 5.1EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
25 ago 2024Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
A vulnerability, which was classified as problematic, has been found in ClassCMS 4.8. Affected by this issue is some unknown functionality of the file /index.php/admin of the component Article Handler. The manipulation of the argument Title leads to basic cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Produtos afetados
n/a · ClassCMS

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →