Anchor CMS
cpe:2.3:a:anchorcms:anchor_cms:*:*:*:*:*:*:*
- 0.12.7
A stored cross-site scripting vulnerability has been identified in Anchor CMS version 0.12.7. This vulnerability allows attackers to inject malicious JavaScript into the page description field within the page creation interface. The injected script is executed when the page is viewed, potentially leading to unauthorized actions or information disclosure.
Exploitation of this vulnerability allows for the execution of arbitrary JavaScript in the context of the user viewing the affected page.
To reproduce this vulnerability, log into the admin interface and navigate to 'Pages' then 'Add Page'. In the 'Description' field, insert a script tag containing JavaScript, such as a script that triggers an alert with the document's domain. After saving the page, the injected script will execute when the page is viewed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.