GouguCMS Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in GouguCMS version 4.08.18. This issue resides in the Record Endpoint, specifically within the file \gougucms-master\app\admin\view\user\record.html. The vulnerability allows low-privileged users to inject malicious scripts into the 'value.content' argument, which are then executed when an administrator accesses the activity logs or records in the backend dashboard. This exploitation could lead to the theft of administrative session cookies or unauthorized actions performed with administrative privileges.

Impact

Successful exploitation allows for blind cross-site scripting, where injected scripts are executed in the context of an administrator's session, potentially leading to session hijacking or unauthorized administrative actions.

Reproduction

To reproduce this vulnerability, a low-privileged user must inject a script payload, such as a JavaScript alert, into a form that submits to the Record Endpoint. Once the payload is stored in the database, an administrator must view the records, triggering the execution of the injected script.

Added: Apr 1, 2026, 2:20 AM
Updated: Apr 1, 2026, 2:20 AM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
5.4
exploitability
6.5
remediation
0.0
relevance
5.1
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.