Qibo CMS Cross-Site Scripting Vulnerability in Internal Message Module

Vulnerability

A stored cross-site scripting vulnerability has been identified in Qibo CMS version 1.0, specifically within the Internal Message Module. This issue arises from inadequate input validation, allowing attackers to inject malicious JavaScript into private messages. When these messages are viewed by other users, including administrators, the scripts are executed in the context of the user's browser.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed when the message is viewed by other users.

Reproduction

To reproduce this vulnerability, send a private message containing a malicious hyperlink that includes JavaScript code, such as one that alerts document cookies. Once the message is sent, it will be stored and executed when the recipient views the message.

Added: Apr 20, 2026, 1:32 PM
Updated: Apr 20, 2026, 1:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
6.3
remediation
0.0
relevance
6.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.