Skip to content

Instantly share code, notes, and snippets.

View sylvieverykawaii's full-sized avatar

sylvieverykawaii

  • Joined Jun 9, 2024
View GitHub Profile
[CVE ID]
CVE-2024-37878
[PRODUCT]
TWCMS - v2.0.3
[VERSION]
TWCMS - v2.0.3
[PROBLEM TYPE]
XSS
[DESCRIPTION]
Cross Site Scripting vulnerablity in TWCMS v.2.0.3 allows a remote attacker to execute arbitrary code via the /TWCMS-gh-pages/twcms/runtime/twcms_view/default,index.htm.php" PHP directly echoes parameters input from external sources