Eura7 CMSmanager Reflected Cross-Site Scripting Vulnerability
Vulnerability
A reflected cross-site scripting vulnerability has been identified in Eura7 CMSmanager versions 4.6 and below. This issue arises from improper neutralization of input in the 'return' GET request parameter, which can be manipulated and sent to a specific endpoint. The vulnerability has been addressed in patch 17012022, which is applicable to all affected versions.
Impact
Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
Remediation
Users can apply patch 17012022 to address this vulnerability. Instructions for applying the patch should be available through Eura7's official channels.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
