Article

    Cyber News / Article / Vulnerability in DRIMO CMS software

    Vulnerability in DRIMO CMS software
    CE
    CERT Polska-2026-06-23

    Vulnerability in DRIMO CMS software

    CERT Polska has received a report about vulnerability in DRIMO CMS software and participated in coordination of its disclosure.

    The vulnerabilityCVE-2026-11772: DRIMO CMS is vulnerable to Reflected XSS viaqparameter in searching functionality. An attacker can crafted an URL that, when opened, results in arbitrary JavaScript execution in the victim's browser.

    Product is in End Of Life phase and will not receive any updates. However, deletinginfo.phpfile mitigates the vulnerability,

    We thank Jarosław Przebinda and Marcin Motwicki for the responsible vulnerability report.

    Original source