CVE-2025-2366 | gougucms 4.08.18 Add Department Page /admin/department/add title cross site scripting
A vulnerability, which was classified as problematic, was found in gougucms 4.08.18. This affects the function add of the file /admin/department/add of the component Add Department Page. The manipulation of the argument title leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-2366. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.