A vulnerability was found in shishuocms 1.1. It has been classified as problematic. Affected is an unknown function of the file /manage/folder/add.json of the component Directory Deletion Page. The manipulation of the argument folderName leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
References
Link | Resource |
---|---|
https://github.com/caigo8/CVE-md/blob/main/shishuocms/%E5%AD%98%E5%82%A8%E5%9E%8BXSS.md | Exploit |
https://vuldb.com/?ctiid.298410 | Permissions Required |
https://vuldb.com/?id.298410 | Permissions Required |
https://vuldb.com/?submit.505754 | Third Party Advisory |
https://github.com/caigo8/CVE-md/blob/main/shishuocms/%E5%AD%98%E5%82%A8%E5%9E%8BXSS.md | Exploit |
Configurations
History
05 Mar 2025, 20:16
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:qzw1210:shishuocms:1.1:*:*:*:*:*:*:* | |
First Time |
Qzw1210 shishuocms
Qzw1210 |
|
References | () https://github.com/caigo8/CVE-md/blob/main/shishuocms/%E5%AD%98%E5%82%A8%E5%9E%8BXSS.md - Exploit | |
References | () https://vuldb.com/?ctiid.298410 - Permissions Required | |
References | () https://vuldb.com/?id.298410 - Permissions Required | |
References | () https://vuldb.com/?submit.505754 - Third Party Advisory | |
Summary |
|
04 Mar 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/caigo8/CVE-md/blob/main/shishuocms/%E5%AD%98%E5%82%A8%E5%9E%8BXSS.md - |
04 Mar 2025, 01:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-04 01:15
Updated : 2025-03-05 20:16
NVD link : CVE-2025-1892
Mitre link : CVE-2025-1892
CVE.ORG link : CVE-2025-1892
JSON object : View
Products Affected
qzw1210
- shishuocms