MCMS, Reflected Cross-Site Scripting (XSS), CVE-2025-22094 (Moderate)

Listen to this Post

How the mentioned CVE works:

This CVE-2025-22094 is a reflected Cross-Site Scripting (XSS) vulnerability in MCMS v6.0.1. The application fails to properly sanitize user-supplied input in one or more of its HTTP request parameters. When an attacker crafts a malicious URL containing a JavaScript payload and tricks a user into clicking it, the application reflects the payload back in the HTTP response without encoding or validation. The user’s browser then receives and executes this malicious script. Since the script runs in the context of the victim’s session, the attacker can potentially steal session cookies, perform actions on behalf of the user, or deface the website, all without direct access to the application’s backend.
Platform: MCMS
Version: v6.0.1

Vulnerability : Reflected XSS

Severity: Moderate

date: 2024-10-23

Prediction: 2024-11-13

What Undercode Say:

curl -s "http://target.com/page?search=<script>alert('XSS')</script>"
<img src=x onerror=alert(document.cookie)>
fetch('/admin/deleteUser', {method: 'POST', body: 'userId=123'})

How Exploit:

1. Attacker crafts malicious URL.

2. Social engineering tricks user.

3. Victim clicks the link.

4. Malicious script executes.

5. Session cookies are stolen.

Protection from this CVE

1. Input validation.

2. Output encoding.

3. Content Security Policy (CSP).

4. HTTPOnly cookies.

5. Sanitize user input.

Impact:

1. Session hijacking.

2. Identity theft.

3. Website defacement.

4. Unauthorized actions.

5. Data exfiltration.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top