S4E just found a medium-severity finding from self signed ssl certificate detection
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jul 8, 2024

CVE-2024-22927 Scanner

CVE-2024-22927 scanner - Cross-Site Scripting (XSS) vulnerability in eyoucms

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-22927
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Eyoucms is a content management system used by developers and website administrators for creating and managing web content. It is popular among small to medium-sized businesses for its ease of use and flexibility. Eyoucms allows users to design, develop, and deploy websites with minimal technical expertise. It is commonly used for building blogs, e-commerce sites, and corporate websites. The system provides various plugins and themes to extend its functionality.

The vulnerability detected in eyoucms v.1.6.5 is a Cross-Site Scripting (XSS) flaw. This allows attackers to execute arbitrary scripts in the context of the user's browser. The malicious script can hijack user sessions, deface websites, or redirect users to malicious sites. It poses a significant security risk by enabling attackers to manipulate web content and perform phishing attacks.

The XSS vulnerability is found in the "func" parameter of the eyoucms application. An attacker can craft a malicious URL that, when accessed, executes arbitrary scripts in the victim's browser. The vulnerability resides in the improper sanitization of user input, allowing script injection. This issue is present in the POST request to the endpoint "/login.php?a=get_upload_list&c=Uploadimgnew". The lack of proper input validation and output encoding makes the application susceptible to XSS attacks.

Exploitation of this vulnerability can lead to severe consequences. Attackers can hijack user sessions and gain unauthorized access to sensitive information. They can perform defacement attacks, altering website content to mislead or harm users. Additionally, attackers can use the vulnerability to execute phishing attacks by redirecting users to malicious websites. Overall, this can compromise the integrity and confidentiality of the affected web application and its users.

Join S4E to safeguard your digital assets with comprehensive vulnerability scanning. Our platform helps you identify and mitigate risks like Cross-Site Scripting (XSS) in eyoucms, ensuring the security of your web applications. Gain insights into potential vulnerabilities, receive detailed remediation steps, and maintain the integrity of your online presence. Sign up now to leverage advanced security tools and protect your business from cyber threats.

References:

Solution Advice
  • Upgrade eyoucms to version 1.6.6 or later.
  • Implement proper input validation and output encoding.
  • Regularly update and patch your CMS software.
  • Conduct routine security audits to identify and fix vulnerabilities.
  • Educate users on the risks of XSS and how to avoid them.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.