Description
Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into page content. Attackers can insert JavaScript payloads in the page modification interface that execute when other users view the compromised page.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Mirabbas Ağalarov
References
www.exploit-db.com/exploits/51604
www.exploit-db.com/exploits/51604 (ExploitDB-51604)
blackcat-cms.org/ (BlackCat CMS Product Webpage)
www.vulncheck.com/...ss-site-scripting-via-page-modification (VulnCheck Advisory: Blackcat CMS 1.4 Stored Cross-Site Scripting via Page Modification)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.