MEDIUM
dameng100 muucmf list.html cross site scripting
Published Mar 26, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.45%
Description
A vulnerability was found in dameng100 muucmf 1.9.5.20260309. The impacted element is an unknown function of the file /admin/config/list.html. Performing a manipulation of the argument Name results in cross site scripting. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
Affected
- 1.9.5.20260309
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-16134 Advisory
- https://thinhneee.github.io/posts/muucmf-xss-config/ exploit
- https://vuldb.com/?ctiid.353152 signaturepermissions-required
- https://vuldb.com/?id.353152 vdb-entrytechnical-description
- https://vuldb.com/?submit.776191 third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-16134 | Advisory | |
| https://thinhneee.github.io/posts/muucmf-xss-config/ | exploit | |
| https://vuldb.com/?ctiid.353152 | signaturepermissions-required | |
| https://vuldb.com/?id.353152 | vdb-entrytechnical-description | |
| https://vuldb.com/?submit.776191 | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Mar 26, 2026
Updated Mar 26, 2026
Reserved Mar 25, 2026
Link CVE-2026-4847
CISA Vulnrichment
Updated Mar 26, 2026
Red Hat
No data
GitHub
No data