Eura7 CMSmanager Reflected Cross-Site Scripting Vulnerability

Vulnerability

A reflected cross-site scripting vulnerability has been identified in Eura7 CMSmanager versions 4.6 and below. This issue arises from improper neutralization of input in the 'return' GET request parameter, which can be manipulated and sent to a specific endpoint. The vulnerability has been addressed in patch 17012022, which is applicable to all affected versions.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.

Remediation

Users can apply patch 17012022 to address this vulnerability. Instructions for applying the patch should be available through Eura7's official channels.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.0
exploitability
6.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.