PHPCMF 4.1.3 has XSS via the first input field to the index.php?s=member&c=register&m=index URI.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://gitee.com/copy_cat/phpcmf/blob/master/README.md | exploit vendor advisory |
http://www.phpcmf.net/version-13.html | vendor advisory |