CVE-2023-31862

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
19/05/2023
Last modified:
21/01/2025

Description

jizhicms v2.4.6 is vulnerable to Cross Site Scripting (XSS). The content of the article published in the front end is only filtered in the front end, without being filtered in the background, which allows attackers to publish an article containing malicious JavaScript scripts by modifying the request package.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jizhicms:jizhicms:2.4.6:*:*:*:*:*:*:*