CVE-2020-12472: XSS
Published Apr 29, 2020
·Updated
MonoX through 5.1.40.5152 allows stored XSS via User Status, Blog Comments, or Blog Description.
Affected Software
1 affected component
Mono MonoX<=5.1.40.5152
Event History
Apr 29, 2020
CVE Published
via MITRE·07:58 PM
Data Sourced
via MITRE·07:58 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-12472?
CVE-2020-12472 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting attacks.
2
How do I fix CVE-2020-12472?
To fix CVE-2020-12472, update MonoX to version 5.1.40.5153 or later.
3
What are the main vulnerabilities associated with CVE-2020-12472?
CVE-2020-12472 allows stored cross-site scripting via the User Status, Blog Comments, or Blog Description fields.
4
Which versions of MonoX are affected by CVE-2020-12472?
MonoX versions up to and including 5.1.40.5152 are affected by CVE-2020-12472.
5
What impacts can CVE-2020-12472 have on users?
Users may experience malicious scripts being executed in their browser if they interact with content affected by CVE-2020-12472.