CVE-2026-3741 | YiFang CMS 2.0.5 D_friendLink.php update linkName cross site scripting (EUVD-2026-10244)
A vulnerability described as problematic has been identified in YiFang CMS 2.0.5. The affected element is the function update of the file app/db/admin/D_friendLink.php. Such manipulation of the argument linkName leads to cross site scripting.
This vulnerability is listed as CVE-2026-3741. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.