Description
WBCE CMS 1.6.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious HTML and CSS to capture user keystrokes. Attackers can upload a crafted HTML file with CSS-based keylogging techniques to intercept password characters through background image requests.
Problem types
URL Redirection to Untrusted Site ('Open Redirect')
Product status
1.6.1
Credits
Mirabbas Ağalarov
References
www.exploit-db.com/exploits/51566 (ExploitDB-51566)
wbce-cms.org/ (WBCE CMS Product Webpage)
www.vulncheck.com/...ripting-and-open-redirect-vulnerability (VulnCheck Advisory: WBCE CMS 1.6.1 Cross-Site Scripting and Open Redirect Vulnerability)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.