CVE-2024-35110: Yzmcms
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.class.php: when logged-in users access a malicious link, their cookies can be captured by an attacker.
Affected products
- Yzmcms Yzmcms: version 7.1 only
Published 2024-05-17. Last modified 2026-06-17.