TomatoCMS Script Insertion Vulnerabilities

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

1) Affected Software * TomatoCMS version 2.0.4. NOTE: Other versions may also be affected. ====================================================================== 2) Severity Rating: Less critical Impact: Cross Site Scripting Where: From remote ====================================================================== 3) Vendor's Description of Software "TomatoCMS is an impressive, powerful Content Management System. It's free and open source licensed under GNU GPL." Product Link: http://tomatocms.com/ ====================================================================== 4) Description of Vulnerability Secunia Research has discovered three vulnerabilities in TomatoCMS, which can be exploited by malicious users to conduct script insertion attacks. Input passed via the "title", "subTitle", and "author" parameters to index.php/admin/news/article/add is not properly sanitised before being displayed to the user. This can be exploited to insert...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息