MRCMS v3.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/group/save.do.
References
Link | Resource |
---|---|
http://mrcms.com | Broken Link |
https://gitee.com/marker/MRCMS | Product |
https://github.com/SimonKang949/Vulnerabilities/issues/6 | Exploit Third Party Advisory Issue Tracking |
https://github.com/SimonKang949/Vulnerabilities/issues/6 | Exploit Third Party Advisory Issue Tracking |
Configurations
History
23 Sep 2025, 18:04
Type | Values Removed | Values Added |
---|---|---|
References | () http://mrcms.com - Broken Link | |
References | () https://gitee.com/marker/MRCMS - Product | |
References | () https://github.com/SimonKang949/Vulnerabilities/issues/6 - Exploit, Third Party Advisory, Issue Tracking | |
CPE | cpe:2.3:a:mrcms:mrcms:3.1.2:*:*:*:*:*:*:* | |
First Time |
Mrcms
Mrcms mrcms |
21 Jul 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/SimonKang949/Vulnerabilities/issues/6 - | |
Summary |
|
|
CWE | CWE-79 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.8 |
18 Jul 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-18 21:15
Updated : 2025-09-23 18:04
NVD link : CVE-2025-50581
Mitre link : CVE-2025-50581
CVE.ORG link : CVE-2025-50581
JSON object : View
Products Affected
mrcms
- mrcms
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')