SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-31862

jizhicms v2.4.6 is vulnerable to Cross Site Scripting (XSS).

MEDIUM 5.4EPSS 0.34%

Does this matter?

Lower severity and a low EPSS score (0.34%). Track it; it rarely justifies an emergency change on its own.

Description

jizhicms v2.4.6 is vulnerable to Cross Site Scripting (XSS). The content of the article published in the front end is only filtered in the front end, without being filtered in the background, which allows attackers to publish an article containing malicious JavaScript scripts by modifying the request package.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.34% probability · 28th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
jizhicms/jizhicms
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.