← Back to search

CVE-2026-36472

5.2 MEDIUMpublic exploit available

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw allows a remote attacker to inject arbitrary JavaScript into an authenticated user's session via unsanitized clickable links on the msg_info page, leading to potential data theft or manipulation.
Exploitability
Exploitation is moderately easy as it requires control over a javascript: URI and placement of such a link on the msg_info page. Authentication is needed for the target user to be affected.
Blast radius
If exploited, this could result in unauthorized access to sensitive information or actions within the authenticated user's session.
Prioritized remediation
Update to the latest version of CuteNews which includes fixes for XSS vulnerabilities.
xssauth-requiredweb-app

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allows a remote attacker to execute arbitrary JavaScript in the context of an authenticated user's session via a javascript: URI rendered as an unsanitized clickable link on the msg_info page.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L

Weaknesses

CWE-79

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.