Junglewise Threat Intelligence

CVE-2025-56304: YzmCMS cross-site scripting in register page referer header

CVE-2025-56304 · Severity: medium · CVSS 6.1 · Published 2025-09-23

Technologies: YzmCMS. Vendors: YzmCMS.

Executive brief

YzmCMS, a content management system used for building websites, contains a security flaw in its registration page. An attacker can trick a user into clicking a malicious link that executes unauthorized scripts in the user's browser. This could lead to the theft of login session information or the performance of unauthorized actions on behalf of the user.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in YzmCMS through version 7.3. The vulnerability is located in the registration page, where the application fails to properly sanitize the HTTP Referer header before reflecting it back into the page source. An unauthenticated remote attacker can exploit this by enticing a user to visit a specially crafted URL or a malicious site that redirects to the registration page with a malicious payload in the Referer header. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized data access.

Affected products

  • YzmCMS YzmCMS up to and including 7.3

Timeline

  • 2025-09-23: advisory: Initial NVD publication

References

Related threats