Executive brief
YzmCMS, a content management system, is vulnerable to a security flaw where it fails to verify the website address provided in incoming web requests. An attacker can exploit this by sending a specially crafted request that tricks the system into inserting malicious scripts into the website's pages. If a user views these compromised pages, the attacker could steal login information, redirect users to fraudulent websites, or deface the site's content.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in YzmCMS up to version 7.5 due to improper neutralization of the HTTP Host header. The root cause is located in /yzmphp/yzmphp.php, where the 'HTTP_HOST' constant is defined directly from the $_SERVER['HTTP_HOST'] superglobal without validation or whitelisting. This constant is subsequently used by the get_url() function in /yzmphp/core/function/global.func.php to construct SITE_URL and other global constants used in templates. A remote, unauthenticated attacker can manipulate the Host header to inject arbitrary HTML or JavaScript (e.g., breaking out of href attributes). This can lead to session hijacking, phishing, or web cache poisoning. As of the advisory date, the vendor has not responded to disclosure attempts.
Affected products
- YzmCMS YzmCMS Up to 7.5
Timeline
- 2026-06-08: disclosed: Initial discovery and PoC created
- 2026-07-09: advisory: CVE published to NVD dataset