CVE-2020-13869: XSS
Published Jun 5, 2020
·Updated
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via a guest name.
Other sources
An issue was discovered in the Comments plugin before 1.5.6 for Craft CMS. There is stored XSS via a guest name.
Affected Software
2 affected componentsFixes available
composer/verbb/comments<1.5.5
1.5.5
verbb Comments Craft Cms<1.5.5
Event History
Jun 5, 2020
CVE Published
via MITRE·06:34 PM
Data Sourced
via MITRE·06:34 PM
Description
May 24, 2022
Advisory Published
via GitHub·05:19 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-13869?
CVE-2020-13869 is classified as a medium severity vulnerability due to its potential for stored XSS attacks.
2
How do I fix CVE-2020-13869?
To fix CVE-2020-13869, update the Comments plugin for Craft CMS to version 1.5.6 or later.
3
What software is affected by CVE-2020-13869?
CVE-2020-13869 affects the Comments plugin for Craft CMS versions prior to 1.5.6.
4
What type of vulnerability is CVE-2020-13869?
CVE-2020-13869 is a stored cross-site scripting (XSS) vulnerability.
5
Can guest names exploit CVE-2020-13869?
Yes, CVE-2020-13869 allows for stored XSS attacks through manipulated guest names in the Comments plugin.