A cross site scripting vulnerability in CSZ CMS 1.2.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'New Pages' field under the 'Pages Content' module.
| Software | From | Fixed in |
|---|---|---|
| cszcms / csz_cms | 1.2.9 | 1.2.9.x |