Executive brief
1CMS is a PHP-based content management system used to manage website content including articles and columns. An authenticated administrator can inject malicious JavaScript into article titles, which executes in the browsers of any other user viewing the affected content, potentially allowing attackers to steal session cookies, exfiltrate sensitive data, or deface the site.
Technical details
An authenticated stored cross-site scripting (XSS) vulnerability exists in the Column Management component of 1CMS v5.6, specifically in the Article Edit page's title field. The vulnerability occurs because user-supplied input in the title field is not properly sanitized or output-encoded before being reflected to other users viewing article list or detail pages. An attacker with administrator privileges can inject arbitrary JavaScript payloads that persist in the database and execute in the browsers of all users viewing the affected article, without requiring additional user interaction. The attack vector is remote and requires valid administrator credentials. No patch information is currently available; remediation requires upgrading to a patched version or implementing strict input validation and output encoding.
Affected products
- ClassCMS 1CMS v5.6
Timeline
- 2026-09-08: disclosed