VYPR
Unrated severityNVD Advisory· Published Oct 28, 2018· Updated Aug 5, 2024

CVE-2018-18724

CVE-2018-18724

Description

An XSS issue was discovered in index.php/admin/category/editcategory?id=73 in YUNUCMS 1.1.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

YUNUCMS 1.1.5 admin category edit page has a stored XSS vulnerability, allowing arbitrary script injection.

Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in YUNUCMS version 1.1.5 in the admin category editing functionality. The issue is triggered via the /index.php/admin/category/editcategory?id=73 endpoint. An attacker with admin panel access can inject arbitrary web scripts or HTML through the category name field, which is stored and executed when the page is viewed [1].

Exploitation

To exploit this vulnerability, an attacker must be authenticated as an administrator. The attacker navigates to the category edit page, inserts a malicious script (e.g., ``) into the category name field, submits the form, and then refreshes the page. The injected script executes in the context of the admin panel, affecting any user who views the edited category [1].

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of any administrator viewing the affected category page. This can lead to session hijacking, defacement, or theft of sensitive data within the admin panel, depending on the injected script. The attack is stored, meaning the payload persists until removed [1].

Mitigation

As of the publication date (2018-10-28), no official patch or fixed version has been released for YUNUCMS 1.1.5. The vendor has not publicly addressed this vulnerability. Administrators should consider sanitizing user input for category names, restricting admin panel access, or migrating to a maintained fork if available [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Yunucms/Yunucmsinferred2 versions
    = 1.1.5+ 1 more
    • (no CPE)range: = 1.1.5
    • (no CPE)range: =1.1.5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.