CVE-2019-5310: Yunucms
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
YUNUCMS 1.1.8 has XSS in app/admin/controller/System.php because crafted data can be written to the sys.php file, as demonstrated by site_title in an admin/system/basic POST request.
Affected products
- Yunucms Yunucms: version 1.1.8 only
Published 2019-01-04. Last modified 2026-06-17.