Medium severity6.1NVD Advisory· Published Nov 20, 2017· Updated May 13, 2026
CVE-2017-16904
CVE-2017-16904
Description
The Public tologin feature in admin.php in LvyeCMS through 3.1 allows XSS via a crafted username that is mishandled during later log viewing by an administrator.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/SQYY/CVE/blob/master/Lvyecms_X.txtnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.