Metrics
Affected Vendors & Products
Mon, 20 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yifang
Yifang cms |
|
| Vendors & Products |
Yifang
Yifang cms |
Mon, 20 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Apr 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in Yifang CMS up to 2.0.5. The impacted element is the function store of the file plugins/yifang_backend_account/logic/admin/L_rbac_admin.php of the component Extended Management Module. The manipulation of the argument Account results in cross site scripting. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Yifang CMS Extended Management L_rbac_admin.php store cross site scripting | |
| Weaknesses | CWE-79 CWE-94 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-20T13:01:44.244Z
Reserved: 2026-04-19T19:12:49.575Z
Link: CVE-2026-6633
Updated: 2026-04-20T12:54:40.403Z
Status : Received
Published: 2026-04-20T12:16:09.303
Modified: 2026-04-20T12:16:09.303
Link: CVE-2026-6633
No data.
OpenCVE Enrichment
Updated: 2026-04-20T13:30:05Z