First published: Wed Apr 29 2020(Updated: )
MonoX through 5.1.40.5152 allows stored XSS via User Status, Blog Comments, or Blog Description.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mono Monox | <=5.1.40.5152 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12472 is classified as a medium severity vulnerability due to its potential for stored cross-site scripting attacks.
To fix CVE-2020-12472, update MonoX to version 5.1.40.5153 or later.
CVE-2020-12472 allows stored cross-site scripting via the User Status, Blog Comments, or Blog Description fields.
MonoX versions up to and including 5.1.40.5152 are affected by CVE-2020-12472.
Users may experience malicious scripts being executed in their browser if they interact with content affected by CVE-2020-12472.