GeniXCMS before 1.1.0 allows remote attackers to cause a denial of service (account blockage) by leveraging the mishandling of certain username substring relationships, such as the admin<script> username versus the admin username, related to register.php, User.class.php, and Type.class.php.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "1.0.2"
}
],
"cpes": [
"cpe:2.3:a:genixcms:genixcms:*:*:*:*:*:*:*:*"
],
"source": "CPE_RANGE",
"vendor_product": "genixcms:genixcms"
}
]
}