A vulnerability was found in FastCMS up to 0.1.5 and classified as problematic. Affected by this issue is some unknown functionality of the component New Article Tab. The manipulation of the argument Title leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-266126 is the identifier assigned to this vulnerability.
References
| Link | Resource |
|---|---|
| https://gitee.com/dianbuapp_admin/fastcms/issues/I8ERNV | Exploit Issue Tracking |
| https://vuldb.com/?ctiid.266126 | Permissions Required VDB Entry |
| https://vuldb.com/?id.266126 | Permissions Required VDB Entry |
| https://gitee.com/dianbuapp_admin/fastcms/issues/I8ERNV | Exploit Issue Tracking |
| https://vuldb.com/?ctiid.266126 | Permissions Required VDB Entry |
| https://vuldb.com/?id.266126 | Permissions Required VDB Entry |
Configurations
History
17 Jun 2026, 05:27
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Xjd2020
Xjd2020 fastcms |
|
| CPE | cpe:2.3:a:xjd2020:fastcms:*:*:*:*:*:*:*:* | |
| References | () https://gitee.com/dianbuapp_admin/fastcms/issues/I8ERNV - Exploit, Issue Tracking | |
| References | () https://vuldb.com/?ctiid.266126 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.266126 - Permissions Required, VDB Entry |
21 Nov 2024, 07:38
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://gitee.com/dianbuapp_admin/fastcms/issues/I8ERNV - | |
| References | () https://vuldb.com/?ctiid.266126 - | |
| References | () https://vuldb.com/?id.266126 - |
24 May 2024, 13:03
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
24 May 2024, 07:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-05-24 07:15
Updated : 2026-06-17 05:27
NVD link : CVE-2023-1111
Mitre link : CVE-2023-1111
CVE.ORG link : CVE-2023-1111
JSON object : View
Products Affected
xjd2020
- fastcms
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
