PT-2026-96127 · Cutenews · Cutenews
CVE-2026-36470
·
Published
2026-09-21
·
Updated
2026-09-22
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
CuteNews version 2.1.2
Description
Cross Site Scripting (XSS) occurs when the application fails to properly sanitize the
Referer header during POST requests to the 'index.php' endpoint. This allows the value of the header to be copied into the response HTML unmodified and unescaped.Recommendations
Update CuteNews to a version newer than 2.1.2.
As a temporary mitigation, restrict or filter the
Referer header in POST requests to 'index.php'.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cutenews