Impact
An authenticated stored cross‑site scripting vulnerability in the Column Management component allows an attacker with valid credentials to inject a crafted payload into the title field, which is then saved to the database and displayed to any user who visits the page. When viewed, the embedded script executes in the victim’s browser, enabling arbitrary JavaScript execution, session hijacking, data theft, and the possibility of defacing or manipulating content. This is a typical reflected‑to‑stored XSS encoded in the application, identified as CWE‑79.
Affected Systems
ClassCMS 1CMS version 5.6 is impacted. No vendor or product list is provided beyond the ClassCMS identifier. The vulnerability exists in the Column Management module's title field handling.
Risk and Exploitability
The access requirement is authentication; an attacker must obtain legitimate user credentials, preferably administrative ones, to inject the payload. The EPSS score is < 1%, and the vulnerability is not listed in CISA KEV, so no current exploitation statistics are known. The admitted CVSS score is 5.4. Stored XSS capable of executing arbitrary scripts poses a high risk to confidentiality, integrity, and availability of affected users’ browsers, and can be leveraged for broader compromise if the victim’s session is hijacked.
OpenCVE Enrichment