Executive brief
YCCMS, a content management system, contains a security flaw in its article management system. An attacker can inject malicious scripts into article titles that are then saved on the server. When other users or administrators view these articles, the scripts execute automatically, potentially allowing the attacker to steal login sessions, redirect users to malicious sites, or deface website content.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in YCCMS 3.4 within the ArticleAction.class.php file. The root cause is the improper neutralization of user-supplied input in the 'title' parameter handled by the add() and getPost() functions. An authenticated attacker with backend access can inject arbitrary HTML or JavaScript into an article title, which is then persisted in the database. The payload executes in the context of any user's browser who views the affected article. This can lead to session hijacking via cookie theft or unauthorized actions performed on behalf of the victim.
Affected products
- YCCMS YCCMS 3.4
Timeline
- 2025-11-20: disclosed: Vulnerability discovered and reported by b1uel0n3
- 2025-11-24: advisory: CVE-2025-64048 published