GHSA-7frh-48wc-2fg4
GitHub Security Advisory
⚠ Unreviewed
MODERATE
Has CVE
Advisory Details
A Cross-Site Scripting (XSS) vulnerability in CSZ CMS 1.3.0 allows attackers to execute arbitrary code via a crafted payload to the Gallery parameter in the YouTube URL fields.
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 30, 2025 6:36 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.