CVE-2020-18654: XSS
Published Jun 22, 2021
·Updated
Cross Site Scripting (XSS) in Wuzhi CMS v4.1.0 allows remote attackers to execute arbitrary code via the "Title" parameter in the component "/coreframe/app/guestbook/myissue.php".
Affected Software
1 affected component
Wuzhicms Wuzhicms=4.1.0
Event History
Jun 22, 2021
CVE Published
via MITRE·03:08 PM
Data Sourced
via MITRE·03:08 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-18654?
The severity of CVE-2020-18654 is medium with a CVSS score of 6.1.
2
How does CVE-2020-18654 affect Wuzhi CMS?
CVE-2020-18654 affects Wuzhi CMS version 4.1.0.
3
How can remote attackers exploit CVE-2020-18654?
Remote attackers can exploit CVE-2020-18654 by executing arbitrary code via the 'Title' parameter in the component '/coreframe/app/guestbook/myissue.php'.
4
Is there a fix available for CVE-2020-18654?
There is no fix available for CVE-2020-18654 at the moment, please refer to the vendor's website for updates.
5
What is the Common Weakness Enumeration (CWE) for CVE-2020-18654?
The Common Weakness Enumeration (CWE) for CVE-2020-18654 is CWE-79, which is a vulnerability related to Cross-Site Scripting (XSS).