Description
SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers can inject malicious JavaScript payloads that will execute in users' browsers when the page is loaded.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
j5s
References
www.exploit-db.com/exploits/49251 (ExploitDB-49251)
www.seacms.net/ (Official Seacms Product Homepage)
www.vulncheck.com/advisories/seacms-checkuser-stored-xss (VulnCheck Advisory: Seacms 11.1 - 'checkuser' Stored XSS)