Executive brief
MCMS, a popular open-source Java content management system, is vulnerable to a security flaw in its search functionality. An attacker can trick a user into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the user's browser. This could lead to the theft of session cookies, unauthorized actions on behalf of the user, or the defacement of the web page as seen by the victim.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in MCMS versions up to and including 6.0.1. The flaw is located in the '/mcms/search.do' endpoint, specifically within the 'content_title' parameter. An attacker can bypass front-end protections to inject malicious JavaScript payloads (e.g., using 'onfocus' and 'autofocus' attributes) that execute when a victim views a specially crafted link or submits a malicious POST request. This vulnerability does not require authentication. Successful exploitation allows for session hijacking or unauthorized manipulation of the user's browser session within the context of the affected site.
Affected products
- mingSoft (Mingfei) MCMS <= 6.0.1
Timeline
- 2025-10-23: disclosed: Initial disclosure of CVE-2025-60837
- 2025-10-23: advisory