CM Table Of Contents - Reflected cross-site scripting (XSS)
4.8
Medium
Summary
Full name
CM Table Of Contents - Clear navigation for better content discovery 1.2.6 - Reflected cross-site scripting (XSS)
Code name
State
Private
Release date
Mar 14, 2025
Affected product
CM Table Of Contents - Clear navigation for better content discovery
Affected version(s)
Version 1.2.6
Vulnerability name
Reflected cross-site scripting (XSS)
Vulnerability type
Remotely exploitable
No
CVSS v4.0 vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L/E:U
CVSS v4.0 base score
4.8
Exploit available
No
CVE ID(s)
Description
CM Table Of Contents - Clear navigation for better content discovery 1.2.6 was found to be vulnerable. The web application dynamically generates web content without validating the source of the potentially untrusted data in myapp/views/backend/admin_importexport.p hp.
Vulnerability
Skims by Fluid Attacks discovered a Reflected cross-site scripting (XSS) in CM Table Of Contents - Clear navigation for better content discovery 1.2.6. The following is the output of the tool:
Skims output
Our security policy
We have reserved the ID CVE-2025-31303 to refer to this issue from now on. Disclosure policy
System Information
Product: CM Table Of Contents - Clear navigation for better content discovery
Version: 1.2.6
Mitigation
There is currently no patch available for this vulnerability.
Timeline
Vulnerability discovered
Mar 14, 2025
Vendor contacted
Mar 14, 2025