CVE-2026-2932 | YiFang CMS up to 2.0.5 Extended Management D_adPosition.php update name/index cross site scripting
A vulnerability was found in YiFang CMS up to 2.0.5. It has been rated as problematic. The impacted element is the function update of the file app/db/admin/D_adPosition.php of the component Extended Management Module. Performing a manipulation of the argument name/index results in cross site scripting.
This vulnerability is reported as CVE-2026-2932. The attack is possible to be carried out remotely. Moreover, an exploit is present.