Junglewise Threat Intelligence

CVE-2024-52680: EyouCMS Cross Site Scripting in admin system configuration

CVE-2024-52680 · Severity: medium · CVSS 6.1 · Published 2025-08-07

Technologies: EyouCMS. Vendors: EyouCMS.

Executive brief

EyouCMS, a content management system used for building websites, contains a security flaw that allows attackers to inject malicious scripts into the administrative login page. If an administrative user clicks a specially crafted link, the attacker could potentially hijack their session, steal sensitive information, or perform unauthorized actions on the website. This could lead to a full compromise of the site's management interface.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in EyouCMS version 1.6.7. The flaw is located in the administrative interface accessible via /login.php?m=admin&c=System&a=web&lang=cn, where user-supplied input is improperly neutralized before being rendered in the web page. An unauthenticated remote attacker can exploit this by tricking a logged-in administrator into visiting a malicious URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session token theft or unauthorized administrative actions. A proof-of-concept has been reported in public repositories.

Affected products

  • EyouCMS EyouCMS 1.6.7

Timeline

  • 2025-08-07: advisory: NVD published the CVE record.
  • 2025-08-07: other: CISA-ADP provided CVSS enrichment.

References

Related threats