Westboy CicadasCMS Cross-Site Scripting Vulnerability in Category Save Function

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Westboy CicadasCMS version 1.0. The issue arises in the category save functionality, where the categoryName parameter is not properly sanitized before being output, allowing for the injection of malicious scripts. This vulnerability can be exploited remotely and requires user interaction.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where injected scripts are executed in the context of the user's browser. This could lead to session hijacking, theft of sensitive information such as cookies, or manipulation of page content.

Reproduction

To reproduce this vulnerability, send a POST request to the /system/cms/category/save endpoint. Include a crafted categoryName parameter that contains malicious script content. The response will confirm the successful addition of the category, indicating that the injected script has been executed.

Added: Sep 27, 2025, 4:17 PM
Updated: Sep 27, 2025, 4:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.3
remediation
0.0
relevance
0.6
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.