An issue was discovered in YzmCMS v5.2. It has XSS via a search/index/archives/pubtime/ query string, as demonstrated by the search/index/archives/pubtime/1526387722/page/1.html URI. NOTE: this does not obtain a user's cookie.
References
Link Resource
https://github.com/yzmcms/yzmcms/issues/7 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-11-07T19:00:00

Updated: 2018-11-07T19:57:01

Reserved: 2018-11-07T00:00:00


Link: CVE-2018-19092

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-11-07T19:29:00.587

Modified: 2018-12-13T15:58:33.597


Link: CVE-2018-19092

JSON object: View

cve-icon Redhat Information

No data.

CWE