Dameng100 Muucmf Reflected Cross-Site Scripting Vulnerability in Auto Reply Function
Vulnerability
A reflected cross-site scripting vulnerability has been identified in Dameng100 Muucmf version 1.9.5.20260309. The issue arises in the channel/admin.Account/autoReply.html file, where the keyword parameter is not properly sanitized, allowing remote attackers to inject and execute arbitrary JavaScript in the context of the user's browser session. This vulnerability was publicly disclosed and is actively exploitable.
Impact
Exploitation of this vulnerability allows for reflected cross-site scripting, where an attacker can execute JavaScript in the context of the user's session, potentially leading to cookie theft or other malicious actions.
Reproduction
To reproduce this vulnerability, send a request to the channel/admin.Account/autoReply.html endpoint with an injected XSS payload in the keyword parameter. The payload will be executed in the user's browser.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
