WTCMS 1.0 contains a reflective cross-site scripting (XSS) vulnerability in the page management background which allows attackers to obtain cookies via a crafted payload entered into the search box.
| Software | From | Fixed in |
|---|---|---|
| wtcms_project / wtcms | 1.0 | 1.0.x |