CVE-2023-34657
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Summary
CVE-2023-34657 is a stored cross-site scripting (XSS) vulnerability affecting Eyoucms version 1.6.2. This issue enables attackers to inject malicious scripts or HTML into the web_recordnum parameter, which is then stored and executed on the targeted user's browser when they view a crafted webpage. Successful exploitation allows attackers to steal sensitive user information or take control of the user's session, potentially leading to serious data breaches. Users are strongly advised to update their Eyoucms installation to a more secure version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.