Executive brief
Juzaweb CMS, a platform used for building and managing websites, contains a security flaw in its banner advertisement management feature. An attacker with administrative access can inject malicious scripts into banner ads, which then execute in the browsers of any visitor who views the site's homepage. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in Juzaweb CMS v5.0.0 within the '/admin/banner-ads' component. The vulnerability is rooted in the 'Add Banner' function when the 'Type' field is set to 'HTML', as the 'Body' field fails to properly neutralize user-supplied JavaScript. An authenticated attacker with administrative privileges can submit a malicious payload that is subsequently rendered and executed in the context of any user (including unauthenticated visitors) who accesses the homepage. This allows for session hijacking, unauthorized redirection, or modification of page content. The vulnerability was disclosed with a Proof of Concept (PoC) involving a simple script alert.
Affected products
- Juzaweb Juzaweb CMS 5.0.0
Timeline
- 2026-05-02: disclosed: Initial vulnerability details and PoC shared on GitHub Gist.
- 2026-05-06: advisory: CVE-2026-36358 published.