iCMS v8.0.0 contains a Cross-Site Scripting (XSS) vulnerability in the User Management component, specifically within the index.html file. This allows remote attackers to execute arbitrary web script or HTML via the regip or loginip parameters.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Mar 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Site Scripting in iCMS User Management Module |
Wed, 25 Mar 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Idreamsoft
Idreamsoft icms |
|
| CPEs | cpe:2.3:a:idreamsoft:icms:8.0.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Idreamsoft
Idreamsoft icms |
Wed, 25 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Icms
Icms icms |
|
| Vendors & Products |
Icms
Icms icms |
Tue, 24 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Tue, 24 Mar 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | iCMS v8.0.0 contains a Cross-Site Scripting (XSS) vulnerability in the User Management component, specifically within the index.html file. This allows remote attackers to execute arbitrary web script or HTML via the regip or loginip parameters. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-03-24T00:00:00.000Z
Updated: 2026-03-24T18:47:24.865Z
Reserved: 2026-03-04T00:00:00.000Z
Link: CVE-2026-30661
Updated: 2026-03-24T18:47:20.341Z
Status : Analyzed
Published: 2026-03-24T15:16:34.350
Modified: 2026-03-25T20:53:28.350
Link: CVE-2026-30661
No data.