CVE-2019-9078

zzcms 2019 has XSS via an arbitrary user/ask.php?do=modify parameter because inc/stopsqlin.php does not block a mixed-case string such as sCrIpT.
References
Link Resource
https://github.com/NS-Sp4ce/ZZCMS-XSS/blob/master/xss.md Exploit Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:zzcms:zzcms:2019:*:*:*:*:*:*:*

Information

Published : 2019-02-24 05:29

Updated : 2019-02-25 05:18


NVD link : CVE-2019-9078

Mitre link : CVE-2019-9078

Products Affected
No products.
CWE