Article
Cyber News / Article / Vulnerability in DRIMO CMS software

CE
CERT Polska-2026-06-23
Vulnerability in DRIMO CMS software
CERT Polska has received a report about vulnerability in DRIMO CMS software and participated in coordination of its disclosure.
The vulnerabilityCVE-2026-11772: DRIMO CMS is vulnerable to Reflected XSS viaqparameter in searching functionality. An attacker can crafted an URL that, when opened, results in arbitrary JavaScript execution in the victim's browser.
Product is in End Of Life phase and will not receive any updates. However, deletinginfo.phpfile mitigates the vulnerability,
We thank JarosÅaw Przebinda and Marcin Motwicki for the responsible vulnerability report.
Related articles
Ab
AbinayaMapLibre Vulnerability Exposes 2.7M Users to Zero-Click Attacks
2 days ago
An
Anne Aarness - Chris PrallCrowdStrike Extends Endpoint Security to Stop Software Supply Chain Attacks
9 days ago
Zi
Ziad GhallebClosing the Blind Spot: Securing Personal Repositories in the Software Supply Chain
29 days ago
You might Also like

Bi
Bill Toulas-1 day ago
Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

in
[email protected] (The Hacker News)-2 days ago
U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

-2 days ago
