CVE 4.8 MEDIUM

GreenCMS Menu Management CustomController.class.php cross site scripting_CVE-2025-14244

4.8 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P

Description

A flaw has been found in GreenCMS 2.3.0603. Affected by this issue is some unknown functionality of the file /Admin/Controller/CustomController.class.php of the component Menu Management Page. This manipulation of the argument Link causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

Basic Information

ID CVE-2025-14244
Source VulDB
Published Dec 8, 2025 at 12:02

Affected Product

Vendor n/a
Product GreenCMS
Version 2.3.0603
Affected Versions n/a GreenCMS 2.3.0603

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.