VDB

CVE-2023-2058

CVE-2023-2058 PUBLISHED CVSS 2.4000000953674316 LOW

A vulnerability was found in EyouCms up to 1.6.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /yxcms/index.php?r=admin/extendfield/mesedit&tabid=12&id=4 of the component HTTP POST Request Handler. The manipulation of the argument web_ico leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225943.

EPSS 0.61% · 45.9th percentile

Risk Scores

CVSS 3.1
2.4000000953674316
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
EPSS Score
0.61%
45.9th percentile

Affected Products

VendorProductVersions
eyoucmseyoucms0
n/aEyouCms1.6.0, 1.6.1, 1.6.2

Timeline

  • Apr 14, 2023 CVE Published
  • Apr 15, 2023 EPSS Score
  • May 23, 2023 EPSS Score
  • Jun 29, 2023 EPSS Score
  • Aug 6, 2023 EPSS Score
  • Sep 13, 2023 EPSS Score
  • Oct 20, 2023 EPSS Score
  • Nov 27, 2023 EPSS Score
  • Jan 4, 2024 EPSS Score
  • Feb 10, 2024 EPSS Score
  • Mar 19, 2024 EPSS Score
  • Apr 26, 2024 EPSS Score

References

…and 47 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›