Executive brief
PivotX CMS, a content management system used for building and managing websites, contains a security vulnerability in its subtitle input field. An attacker with low-level access can inject malicious scripts that run when other users, such as administrators, view the affected content. This can lead to unauthorized actions being performed on behalf of the victim, potentially resulting in full site takeover or data theft.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in PivotX CMS v.3.0.0 RC 3 due to improper neutralization of input in the subtitle field (CWE-79). A remote attacker with low-privileged credentials can inject malicious JavaScript into this field. When a victim (such as an administrator) views the page containing the malicious subtitle, the script executes in their browser context. According to the advisory, this XSS can be leveraged to achieve privilege escalation and subsequent remote code execution (RCE). The attack requires network connectivity and minimal user interaction from the victim.
Affected products
- PivotX PivotX CMS 3.0.0 RC 3
Timeline
- 2025-09-22: disclosed
- 2025-09-22: advisory