Dayrui XunRuiCMS Cross-Site Scripting Vulnerability in Data Validation Component

Vulnerability

A cross-site scripting (XSS) vulnerability has been identified in Dayrui XunRuiCMS versions through 4.7.1. The issue resides in the Add Data Validation Page component, specifically within the file /admind45f74adbd95.php?c=field&m=add&rname=site&rid=1&page=1. The vulnerability is triggered by manipulating the data[name] argument, allowing for the injection of malicious scripts. This vulnerability can be exploited remotely and has been publicly disclosed, with an available proof-of-concept exploit.

Impact

Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.

Reproduction

To reproduce this vulnerability, navigate to the 'Settings' menu, then go to 'Project Information' and select 'Data Validation'. Add a new validation and enter a regular expression that includes a script injection, such as an image tag with an 'onerror' event. Once the validation prompt is saved, the injected script will execute, demonstrating the cross-site scripting vulnerability.

Added: Dec 4, 2025, 3:30 PM
Updated: Dec 4, 2025, 6:24 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
1.7
exploitability
6.5
remediation
0.0
relevance
1.3
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.