First published: Fri Apr 30 2021(Updated: )
Cross Site Scripting (XSS) in yzmCMS v5.2 allows remote attackers to execute arbitrary code by injecting commands into the "referer" field of a POST request to the component "/member/index/login.html" when logging in.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yzmcms Yzmcms | =5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this cross-site scripting vulnerability is CVE-2020-18084.
CVE-2020-18084 has a severity rating of medium (6.1).
The cross-site scripting vulnerability in yzmCMS v5.2 occurs when remote attackers inject commands into the 'referer' field of a POST request to the '/member/index/login.html' component during the login process.
Remote attackers can exploit the cross-site scripting vulnerability in yzmCMS v5.2 by injecting arbitrary code into the 'referer' field of a POST request to the '/member/index/login.html' component.
Yes, a fix for CVE-2020-18084 is available. It is recommended to update to a version of yzmCMS that is not affected by the vulnerability.