iCMS v8.0.0 contains a Cross-Site Scripting (XSS) vulnerability in the User Management component, specifically within the index.html file. This allows remote attackers to execute arbitrary web script or HTML via the regip or loginip parameters.
References
| Link | Resource |
|---|---|
| https://wang1rrr.github.io/2026/02/09/CVE-Report-iCMS-v8.0.0-XSS/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-03-24 15:16
Updated : 2026-06-17 10:32
NVD link : CVE-2026-30661
Mitre link : CVE-2026-30661
CVE.ORG link : CVE-2026-30661
JSON object : View
Products Affected
idreamsoft
- icms
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
