CVE-2018-7547: Lingyun Lyadmin
Medium severity, CVSS 4.8. EPSS: 0.5% chance of exploitation in the next 30 days.
lyadmin 1.x has XSS via the config[WEB_SITE_TITLE] parameter to the /admin.php?s=/admin/config/groupsave.html URI.
Affected products
- Lingyun Lyadmin: from 1.0.0, up to and including 1.2.0
Published 2018-02-27. Last modified 2026-06-17.