ZeroHour

CVE-2021-39428

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p44
Published
()
Modified
Description

Cross Site Scripting (XSS) vulnerability in Users.php in eyoucms 1.5.4 allows remote attackers to run arbitrary code and gain escalated privilege via the filename for edit_users_head_pic.

Vendors
eyoucms
Products
eyoucms
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.