CVE-2020-13870: XSS
Published Jun 5, 2020
·Updated
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name.
Affected Software
2 affected componentsFixes available
composer/verbb/comments<1.5.5
1.5.5
verbb Comments Craft Cms<1.5.5
Event History
Jun 5, 2020
CVE Published
via MITRE·06:34 PM
Data Sourced
via MITRE·06:34 PM
Description
May 24, 2022
Advisory Published
via GitHub·05:19 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-13870?
CVE-2020-13870 is classified as a critical severity vulnerability due to its potential for stored XSS attacks.
2
How do I fix CVE-2020-13870?
To fix CVE-2020-13870, update the Comments plugin to version 1.5.5 or later.
3
What types of attacks can CVE-2020-13870 facilitate?
CVE-2020-13870 can facilitate stored cross-site scripting (XSS) attacks through malicious input in asset volume names.
4
Which versions of the Comments plugin are affected by CVE-2020-13870?
CVE-2020-13870 affects versions of the Comments plugin prior to 1.5.5.
5
What is the impact of CVE-2020-13870 on Craft CMS users?
The impact of CVE-2020-13870 on Craft CMS users includes potential unauthorized script execution in user browsers, leading to data theft or session hijacking.