VDB

CVE-2023-2058

CVE-2023-2058 PUBLISHED CVSS 3.299999952316284 LOW

A vulnerability was found in EyouCms up to 1.6.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /yxcms/index.php?r=admin/extendfield/mesedit&tabid=12&id=4 of the component HTTP POST Request Handler. The manipulation of the argument web_ico leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-225943.

EPSS 0.61% · 47.4th percentile

Risk Scores

CVSS 2.0
3.299999952316284
EPSS Score
0.61%
47.4th percentile

Affected Products

VendorProductVersions
eyoucmseyoucms0
n/aEyouCms1.6.0, 1.6.1, 1.6.2

Timeline

  • Apr 14, 2023 CVE Published
  • Apr 15, 2023 EPSS Score
  • May 23, 2023 EPSS Score
  • Jul 1, 2023 EPSS Score
  • Aug 8, 2023 EPSS Score
  • Sep 15, 2023 EPSS Score
  • Oct 23, 2023 EPSS Score
  • Dec 1, 2023 EPSS Score
  • Jan 8, 2024 EPSS Score
  • Feb 15, 2024 EPSS Score
  • Mar 24, 2024 EPSS Score
  • May 2, 2024 EPSS Score

References

…and 47 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›