Medium severity6.1NVD Advisory· Published Nov 16, 2017· Updated May 13, 2026
CVE-2017-16866
CVE-2017-16866
Description
dayrui FineCms 5.2.0 before 2017.11.16 has Cross Site Scripting (XSS) in core/M_Controller.php via the DR_URI field.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- gitee.com/dayrui/finecms/commit/09d4f3c1a1b8598ce8967e158b16b9fe44936c50nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.