A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\view\user\record.html of the component Record Endpoint. Performing a manipulation of the argument value.content results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\view\user\record.html of the component Record Endpoint. Performing a manipulation of the argument value.content results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | gougucms Record Endpoint record.html cross site scripting | |
| First Time appeared |
Gougucms
Gougucms gougucms |
|
| Weaknesses | CWE-79 CWE-94 |
|
| CPEs | cpe:2.3:a:gougucms:gougucms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gougucms
Gougucms gougucms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-01T01:30:16.723Z
Reserved: 2026-03-31T16:00:50.059Z
Link: CVE-2026-5249
No data.
Status : Received
Published: 2026-04-01T02:16:03.890
Modified: 2026-04-01T02:16:03.890
Link: CVE-2026-5249
No data.
OpenCVE Enrichment
No data.