VulnerabilityAnalyzed
CVE-2023-53891
Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into page content.
MEDIUM 5.1EPSS 0.24%
Does this matter?
Lower severity and a low EPSS score (0.24%). Track it; it rarely justifies an emergency change on its own.
Description
Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into page content. Attackers can insert JavaScript payloads in the page modification interface that execute when other users view the compromised page.
- CVSS 4.0
- 5.1 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.24% probability · 16th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- blackcat-cms/blackcat cms
- Source
- disclosure@vulncheck.com
References
- https://blackcat-cms.org/Product
- https://www.exploit-db.com/exploits/51604Exploit, Third Party Advisory, VDB Entry
- https://www.vulncheck.com/advisories/blackcat-cms-stored-cross-site-scripting-via-page-modificationThird Party Advisory
- https://www.exploit-db.com/exploits/51604Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.