Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into page content. Attackers can insert JavaScript payloads in the page modification interface that execute when other users view the compromised page.
References
| Link | Resource |
|---|---|
| https://blackcat-cms.org/ | Product |
| https://www.exploit-db.com/exploits/51604 | Exploit Third Party Advisory VDB Entry |
| https://www.vulncheck.com/advisories/blackcat-cms-stored-cross-site-scripting-via-page-modification | Third Party Advisory |
| https://www.exploit-db.com/exploits/51604 | Exploit Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2025-12-15 21:15
Updated : 2025-12-17 15:35
NVD link : CVE-2023-53891
Mitre link : CVE-2023-53891
CVE.ORG link : CVE-2023-53891
JSON object : View
Products Affected
blackcat-cms
- blackcat_cms
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
