High severity7.1NVD Advisory· Published May 6, 2024· Updated Jun 17, 2026
CVE-2024-28725
CVE-2024-28725
Description
Cross Site Scripting (XSS) vulnerability in YzmCMS 7.0 allows attackers to run arbitrary code via Ads Management, Carousel Management, and System Settings.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4Patches
Vulnerability mechanics
References
2- github.com/asenzhenshuai/DongDong/blob/main/yzmcms-xss.pdfnvdExploitThird Party Advisory
- github.com/asenzhenshuai/DongDong/issues/1nvdExploitIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.