TuziCMS 2.0.6 has XSS via the PATH_INFO to a group URI, as demonstrated by index.php/article/group/id/2/.
References
Link | Resource |
---|---|
https://github.com/yeyinshi/tuzicms/issues/5 | Exploit Issue Tracking Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2019-09-21T17:02:24
Updated: 2019-09-21T17:02:24
Reserved: 2019-09-21T00:00:00
Link: CVE-2019-16657
JSON object: View
NVD Information
Status : Analyzed
Published: 2019-09-21T18:15:11.227
Modified: 2019-09-23T13:51:41.417
Link: CVE-2019-16657
JSON object: View
Redhat Information
No data.
CWE