{"id":"CVE-2026-36472","published":"2026-09-21T16:17:08.210","lastModified":"2026-09-21T16:17:08.210","description":"CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allows a remote attacker to execute arbitrary JavaScript in the context of an authenticated user's session via a javascript: URI rendered as an unsanitized clickable link on the msg_info page.","cvssScore":5.2,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://github.com/CuteNews/cutenews-2.0","tags":[]},{"url":"https://github.com/CuteNews/cutenews-2.0/blob/master/core/core.php","tags":[]},{"url":"https://github.com/UmbraDeorum/cutenews-2.0-CVEs-2026-Disclosure","tags":[]}],"exploitRefs":[{"url":"https://github.com/CuteNews/cutenews-2.0","tags":[]},{"url":"https://github.com/CuteNews/cutenews-2.0/blob/master/core/core.php","tags":[]},{"url":"https://github.com/UmbraDeorum/cutenews-2.0-CVEs-2026-Disclosure","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows a remote attacker to inject arbitrary JavaScript into an authenticated user's session via unsanitized clickable links on the msg_info page, leading to potential data theft or manipulation.","exploitability":"Exploitation is moderately easy as it requires control over a javascript: URI and placement of such a link on the msg_info page. Authentication is needed for the target user to be affected.","blast_radius":"If exploited, this could result in unauthorized access to sensitive information or actions within the authenticated user's session.","remediation":"Update to the latest version of CuteNews which includes fixes for XSS vulnerabilities.","tags":["xss","auth-required","web-app"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:29:52.103Z"}}