Medium severity5.4NVD Advisory· Published Oct 27, 2023· Updated Jun 17, 2026
CVE-2023-46394
CVE-2023-46394
Description
A stored cross-site scripting (XSS) vulnerability in /home/user/edit_submit of gougucms v4.08.18 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the headimgurl parameter.
Affected products
2Patches
Vulnerability mechanics
References
1- gitee.com/gouguopen/gougucms/issues/I88TC0nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.