Arbitrary Code Execution and Privilege Escalation via Cross Site Scripting (XSS) in Sunlight CMS v.8.0.1

Arbitrary Code Execution and Privilege Escalation via Cross Site Scripting (XSS) in Sunlight CMS v.8.0.1

CVE-2023-48201 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Cross Site Scripting (XSS) vulnerability in Sunlight CMS v.8.0.1, allows remote authenticated attackers to execute arbitrary code and escalate privileges via a crafted script to the Content text editor component.

Learn more about our Cms Pen Testing.