Rubysec iconRubysecSep 4, 2026

GHSA-g7vv-4mjj-6fgm (alchemy_cms): Account Takeover & Privilege-Escalation To Admin via Stored XSS in Menu Node Name Rendered in Page Properties Configure Dialog

The payload executes with the Admin's session privileges, allowing an attacker to perform administrative actions and create an attacker-controlled administrator account, resulting in full account takeover and privilege escalation.

Share this story

Send the public story page.

Useful takeaways from this story.

The payload executes with the Admin's session privileges, allowing an attacker to perform administrative actions and create an attacker-controlled administrator account, resulting in full account takeover...

An improper input sanitization vulnerability in the Page Properties menu node rendering allows Author-level users to inject stored JavaScript that executes in an Admin's browser when they open the Configure...

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

The payload executes with the Admin's session privileges, allowing an attacker to perform administrative actions and create an attacker-controlled administrator account, resulting in full account takeover and privilege escalation. An improper input sanitization vulnerability in the Page Properties menu node rendering allows Author-level users to inject stored JavaScript that executes in an Admin's browser when they open the Configure dialog for a page containing the malicious node.

How it works

  • An improper input sanitization vulnerability in the Page Properties menu node rendering allows Author-level users to inject stored JavaScript that executes in an Admin's browser when they open the Configure...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app