← Back

CVE-2026-29934

nvd nist
Published: Mar 26, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

A reflected cross-site scripting (XSS) vulnerability in the /admin/menus component of Lightcms v2.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via modifying the referer value in the request header.

Affected (1)

Lightcms
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.0

References (1)

Source: cve@mitre.org
ExploitIssue TrackingMitigation

Timeline

No history available yet.