CVE-2020-18084: XSS
Cross Site Scripting (XSS) in yzmCMS v5.2 allows remote attackers to execute arbitrary code by injecting commands into the "referer" field of a POST request to the component "/member/index/login.html" when logging in.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this cross-site scripting vulnerability?
The vulnerability ID for this cross-site scripting vulnerability is CVE-2020-18084.
What is the severity rating of CVE-2020-18084?
CVE-2020-18084 has a severity rating of medium (6.1).
How does the cross-site scripting vulnerability in yzmCMS v5.2 occur?
The cross-site scripting vulnerability in yzmCMS v5.2 occurs when remote attackers inject commands into the 'referer' field of a POST request to the '/member/index/login.html' component during the login process.
How can remote attackers exploit the cross-site scripting vulnerability in yzmCMS v5.2?
Remote attackers can exploit the cross-site scripting vulnerability in yzmCMS v5.2 by injecting arbitrary code into the 'referer' field of a POST request to the '/member/index/login.html' component.
Is there a fix available for CVE-2020-18084?
Yes, a fix for CVE-2020-18084 is available. It is recommended to update to a version of yzmCMS that is not affected by the vulnerability.