Executive brief
PublicCMS, a content management system, contains a security flaw in its site configuration settings. An attacker with access to the management console can insert malicious scripts into configuration descriptions. If another administrator views these settings, the script could execute in their browser, potentially leading to unauthorized actions or the theft of sensitive session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in PublicCMS V5.202506.d within the site configuration management module. The vulnerability is located in the 'description' field when adding or modifying configuration items. An authenticated attacker with permissions to modify site settings can inject a malicious JavaScript payload into this field. The payload is executed when an administrative user navigates to the 'Modify Configuration Item' view for the affected entry. This can lead to session hijacking or unauthorized administrative actions within the context of the victim's browser.
Affected products
- PublicCMS PublicCMS V5.202506.d
Timeline
- 2026-06-15: disclosed: Initial disclosure via GitHub Gist and NVD publication.