A stored Cross Site Scripting (xss) vulnerability in the "content management" feature in AnQiCMS v.3.4.11 allows a remote attacker to execute arbitrary code via a crafted script to the title, categoryTitle, and tmpTag parameters.
Metrics
Affected Vendors & Products
References
History
Thu, 31 Jul 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Thu, 31 Jul 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A stored Cross Site Scripting (xss) vulnerability in the "content management" feature in AnQiCMS v.3.4.11 allows a remote attacker to execute arbitrary code via a crafted script to the title, categoryTitle, and tmpTag parameters. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-07-31T00:00:00.000Z
Updated: 2025-07-31T19:45:40.410Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-50270

Updated: 2025-07-31T19:45:32.320Z

Status : Awaiting Analysis
Published: 2025-07-31T15:15:36.687
Modified: 2025-07-31T20:15:43.270
Link: CVE-2025-50270

No data.