Boom CMS assets-manager add cross site scripting
Description
A vulnerability has been found in Boom CMS 8.0.7 and classified as problematic. Affected by this vulnerability is the function add of the component assets-manager. The manipulation of the argument title/description leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-235057 was assigned to this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Boom CMS 8.0.7 suffers from a stored XSS vulnerability in the assets-manager component via the album title and description fields.
Vulnerability
A stored cross-site scripting (XSS) vulnerability exists in Boom CMS version 8.0.7 within the assets-manager component. The add function does not sanitize the title and description parameters when creating or updating an album, allowing arbitrary JavaScript to be injected and stored. The vulnerable endpoint is asset-manager/albums/[ID] [1].
Exploitation
An attacker with network access to the Boom CMS instance can send a crafted HTTP PUT request to the album endpoint with malicious payloads in the name and description JSON fields. The PoC demonstrates injection of script code that is then reflected when the album page is loaded. No authentication is required if the endpoint is exposed, but typically the attacker would need a valid session to modify albums. The exploit has been publicly disclosed [1].
Impact
Successful exploitation leads to stored XSS, enabling an attacker to execute arbitrary JavaScript in the context of a victim's browser when they view the affected album. This can result in session hijacking, defacement, or theft of sensitive data. The attack is remote and does not require elevated privileges beyond the ability to modify album metadata [1].
Mitigation
As of the publication date (2023-07-20), no official patch has been released for Boom CMS 8.0.7. Users should restrict access to the assets-manager endpoints, apply input validation and output encoding for the title and description fields, or upgrade to a patched version if available. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Boom/CMSv5Range: 8.0.7
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
4- seclists.org/fulldisclosure/2023/Jul/33mitreexploitmailing-list
- vuldb.commitresignaturepermissions-required
- vuldb.commitrevdb-entrytechnical-description
- www.vulnerability-lab.com/get_content.phpmitrerelated
News mentions
0No linked articles in our index yet.