MEDIUM

CVE-2026-11772

2026-06-23 CVSS v4.0
CVSS
5.1

Description

DRIMO CMS is vulnerable to Reflected XSS via q parameter in searching functionality. An attacker can prepare an URL that, when opened, results in arbitrary JavaScript execution in the victim's browser.

Product is in End Of Life phase and will not receive any updates. However, deleting info.php file mitigates the vulnerability,

Summary dbcve.org

DRIMO CMS contains a reflected XSS vulnerability in its search functionality where the 'q' parameter is not properly sanitized. An attacker can craft a malicious URL containing JavaScript code that will execute in the victim's browser when they visit the crafted link.

Mitigation

Delete the info.php file from the server, which eliminates the attack vector. This is the recommended workaround since the product is end-of-life and will not receive official security patches.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.55%
Probability of exploitation in next 30 days
45.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE