Yifang CMS Cross-Site Scripting Vulnerability in Article Management Module
Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Yifang CMS versions through 2.0.2, specifically within the Article Management Module. The issue arises from the manipulation of the 'Default Value' argument, allowing for the injection of malicious scripts. This vulnerability can be exploited remotely, and the details of the exploit have been publicly disclosed.
Impact
Exploitation of this vulnerability allows for cross-site scripting, where an attacker can inject malicious scripts that are executed in the context of the user's browser.
Reproduction
To reproduce this vulnerability, log into the Yifang CMS backend and navigate to the Article Management Module. Click on 'Field Settings' and enter a JavaScript payload in the 'Default Values' section. After saving, the injected script will execute, demonstrating the cross-site scripting vulnerability. This exploit can be used to steal cookies or session information from the administrator.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
