Junglewise Threat Intelligence

CVE-2026-88746: idccms V1.70 cross-site scripting in makeDiy_deal.php

CVE-2026-88746 · Severity: high · CVSS 7.1 · Published 2026-09-21

Executive brief

idccms is a content management system used to build and manage websites. A cross-site scripting (XSS) vulnerability in the administrative interface allows an attacker to inject malicious scripts that execute in administrators' browsers, potentially leading to account compromise, unauthorized changes to site content, or theft of sensitive data. The vulnerability exists in the /admin/makeDiy_deal.php file and affects version 1.70.

Technical details

A stored or reflected XSS vulnerability exists in the /admin/makeDiy_deal.php administrative function in idccms V1.70, allowing unauthenticated or authenticated attackers to inject arbitrary JavaScript code. The vulnerability likely stems from insufficient input validation and output encoding of user-supplied parameters. Successful exploitation requires social engineering an administrator to click a malicious link or could occur through stored payload if input persists in the database.

Affected products

  • idccms V1.70

Timeline

  • 2026-09-21: disclosed

References