Anchor CMS Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in Anchor CMS version 0.12.7. This vulnerability allows attackers to inject malicious JavaScript into the page description field within the page creation interface. The injected script is executed when the page is viewed, potentially leading to unauthorized actions or information disclosure.

Impact

Exploitation of this vulnerability allows for the execution of arbitrary JavaScript in the context of the user viewing the affected page.

Reproduction

To reproduce this vulnerability, log into the admin interface and navigate to 'Pages' then 'Add Page'. In the 'Description' field, insert a script tag containing JavaScript, such as a script that triggers an alert with the document's domain. After saving the page, the injected script will execute when the page is viewed.

Added: Jun 9, 2025, 5:24 PM
Updated: Jun 9, 2025, 5:24 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
1.7
exploitability
6.5
remediation
0.0
relevance
0.2
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.