Medium severity5.4NVD Advisory· Published Aug 21, 2024· Updated Jun 17, 2026
CVE-2024-42939
CVE-2024-42939
Description
A cross-site scripting (XSS) vulnerability in the component /index/index.html of YZNCMS v1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the configured remarks text field.
Affected products
2Patches
Vulnerability mechanics
References
1- github.com/tcyba/open_vul/blob/main/yzncms%20has%20a%20storage%20xss%20vulnerability.pdfnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.