ZeroHour

CVE-2021-36654

PoC ×2
CVSS 3.1
5.4 medium
EPSS
2%p79
Published
()
Modified
Description

CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while updating the theme.

Vendors
cmsuno project
Products
cmsuno
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.