Retour à la veille

CVE-2026-36470

Publié : 21 septembre 2026
Modifié : 21 septembre 2026
Lien officiel NVD

Description détaillée

CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied into the response HTML unmodified/unescaped during POST messages to index.php.

Références et Patchs