60CycleCMS 2.5.2 contains a cross-site scripting (XSS) vulnerability in news.php that allows attackers to inject malicious scripts through GET parameters. Attackers can craft malicious URLs with XSS payloads targeting the 'etsu' and 'ltsu' parameters to execute arbitrary scripts in victim's browsers. This issue does not involve SQL injection.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Feb 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | 60CycleCMS 2.5.2 contains a cross-site scripting (XSS) vulnerability in news.php that allows attackers to inject malicious scripts through GET parameters. Attackers can craft malicious URLs with XSS payloads targeting the 'etsu' and 'ltsu' parameters to execute arbitrary scripts in victim's browsers. This issue does not involve SQL injection. | |
| Title | 60CycleCMS 2.5.2 - 'news.php' Cross-site Scripting (XSS) Vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-03T16:52:44.666Z
Reserved: 2026-02-01T13:16:06.490Z
Link: CVE-2020-37111
No data.
Status : Received
Published: 2026-02-03T18:16:11.180
Modified: 2026-02-03T18:16:11.180
Link: CVE-2020-37111
No data.
OpenCVE Enrichment
No data.