ZeroHour

CVE-2024-28725

PoC ×2
CVSS 3.1
7.1 high
EPSS
<1%p28
Published
()
Modified
Description

Cross Site Scripting (XSS) vulnerability in YzmCMS 7.0 allows attackers to run arbitrary code via Ads Management, Carousel Management, and System Settings.

Vendors
yzmcms
Products
yzmcms
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.