CVE-2019-16130
Description
YII2-CMS v1.0 has stored XSS via the name field in the contact form, allowing arbitrary script execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
YII2-CMS v1.0 has stored XSS via the name field in the contact form, allowing arbitrary script execution.
Vulnerability
YII2-CMS v1.0 suffers from a stored cross-site scripting (XSS) vulnerability in the contact form. The name field in protected\core\modules\home\models\Contact.php is not sanitized or length-restricted, despite other fields having validation rules. An attacker can inject malicious JavaScript payloads into the name field, which are then stored on the server and executed when the administrator or any user views the contact submission details [1][2].
Exploitation
The attack is performed by sending a POST request to /contact.html with a crafted Contact[name] parameter containing script tags, such as ``. No authentication is required to submit the form. The payload is stored in the database and rendered without proper output encoding, leading to automatic execution in the browsers of users who access the contact message list or detail page [2].
Impact
A remote, unauthenticated attacker can execute arbitrary JavaScript in the context of any user viewing the contact submissions, including administrators. This can lead to session hijacking, credential theft, or defacement. The CVSS v3.1 score reflects medium severity, but if an admin is targeted, the impact can be elevated [1].
Mitigation
The vendor has not released a patched version. The issue was reported in 2019 and remains unaddressed in the latest available code. Mitigations include manually implementing input validation and output encoding for the name field, or disabling the contact form if not required [1][2].
AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
yii2mod/yii2-cmsPackagist | < 1.9.2 | 1.9.2 |
Affected products
2- YII2-CMS/YII2-CMSdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/advisories/GHSA-rfh8-25h9-mhgfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-16130ghsaADVISORY
- www.iwantacve.cn/index.php/archives/277ghsaWEB
- www.iwantacve.cn/index.php/archives/277/mitrex_refsource_MISC
- github.com/weison-tech/yii2-cms/issues/2ghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.