PyroCMS
cpe:2.3:a:pyrocms:pyrocms:*:*:*:*:*:*:*
- 3.0.1
A stored cross-site scripting vulnerability has been identified in PyroCMS version 3.0.1. This issue resides within the admin redirects configuration, where attackers can inject malicious scripts. By placing a payload in the 'Redirect From' field, it is possible to execute arbitrary JavaScript when administrators access the redirects page.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the affected page.
To reproduce this vulnerability, log into the admin panel and navigate to the redirects management page. Once there, edit an existing redirect or create a new one. In the 'Redirect From' field, enter a script payload, such as a SVG image tag with an 'onload' event. After saving the redirect, go back to the redirects overview page. The injected script will execute, demonstrating the cross-site scripting vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.