Sceawere

Vulnerability Detail

CVE-2026-105124UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WCMS Stored Cross-Site Scripting

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
3h ago
Vendor
vincent-peugnet
Product
wcms
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or comment URLs echoed into href attributes in editrightbar.php, executing script with administrator or editor privileges.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-10-04T00:16:35.853Z",
  "pubdate": "2026-10-04T00:16:35.853Z",
  "executiveSummary": "W (vincent-peugnet/wcms) versions through 3.18.0 are susceptible to a stored Cross-Site Scripting (XSS) vulnerability. This vulnerability arises due to the improper neutralization of user-supplied input before rendering it in administrative interfaces.\nUnauthenticated attackers can leverage this flaw to inject malicious scripts into the application. The primary attack vectors involve the login user field and the visitor comment website field. Once injected, these scripts execute within the browser context of an administrator or editor when they access the affected management pages.\nThe impact is significant, as successful exploitation enables attackers to execute arbitrary JavaScript under the privileges of the victim. This could lead to unauthorized actions, session hijacking, or the exfiltration of sensitive information from the administrative panel.\nBecause the vulnerability requires no prior authentication, it poses a notable risk to the integrity and confidentiality of the WCMS installation. Administrators should prioritize addressing this issue to prevent potential account compromise or unauthorized management operations.",
  "technicalDetails": "The vulnerability resides in the application's failure to perform adequate input sanitization or output encoding on user-controllable data before reflecting it in backend administrative views.\nIn the first vector, an unauthenticated attacker can submit a crafted payload within the username field during a failed authentication attempt. The application logs these attempts, and the 'adminlog.php' file renders the user-supplied input without appropriate character escaping. When an administrator views the logs, the browser parses the injected script, leading to stored XSS execution.\nThe second vector involves the visitor comment feature, specifically the 'website' field. When a user submits a comment, the provided website URL is stored in the database. This data is subsequently echoed into the 'href' attribute of an HTML anchor element within 'editrightbar.php'. An attacker can inject a payload using a 'javascript:' pseudo-protocol or by breaking out of the attribute context to introduce script tags. When an editor or administrator reviews comments via 'editrightbar.php', the malicious code is executed.\nThe attack flow for the login vector is as follows: 1) The attacker sends a POST request with an XSS payload in the username field. 2) The server logs the failed attempt, storing the payload in the application logs. 3) An administrator navigates to the 'adminlog.php' administrative page. 4) The server fetches the logged data and renders it directly to the response buffer without sanitization. 5) The browser interprets the payload as executable script within the administrative session.\nThe attack flow for the comment vector is: 1) The attacker submits a comment with a malicious payload in the website URL field. 2) The application persists this entry to the backend database. 3) An administrator or editor accesses 'editrightbar.php' to manage or review submitted content. 4) The application pulls the malicious string from the database and embeds it into an 'href' attribute. 5) Upon rendering, the malicious JavaScript executes with the permissions of the logged-in user, potentially allowing the attacker to capture session cookies or perform unauthorized configuration changes via the CMS administrative API.\nThis vulnerability highlights a critical failure in following secure coding practices regarding Output Encoding. By failing to treat all stored data as untrusted, the application allows for the persistent execution of client-side scripts, effectively bypassing authentication controls by targeting the higher-privileged sessions of administrators."
}
CVE-2026-105124: WCMS Stored Cross-Site Scripting (MEDIUM Severity, CVSS: 6.1) | Sceawere