Skip to content

Instantly share code, notes, and snippets.

@sylvieverykawaii
Created June 11, 2024 20:08
Show Gist options
  • Save sylvieverykawaii/243f1756151bee027725c6961d8c1ba9 to your computer and use it in GitHub Desktop.
Save sylvieverykawaii/243f1756151bee027725c6961d8c1ba9 to your computer and use it in GitHub Desktop.
CVE-2024-37878
[CVE ID]
CVE-2024-37878
[PRODUCT]
TWCMS - v2.0.3
[VERSION]
TWCMS - v2.0.3
[PROBLEM TYPE]
XSS
[DESCRIPTION]
Cross Site Scripting vulnerablity in TWCMS v.2.0.3 allows a remote attacker to execute arbitrary code via the /TWCMS-gh-pages/twcms/runtime/twcms_view/default,index.htm.php" PHP directly echoes parameters input from external sources
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment