CVE-2020-19553: XSS
Published Sep 21, 2021
·Updated
Cross Site Scripting (XSS) vlnerability exists in WUZHI CMS up to and including 4.1.0 in the config function in coreframe/app/attachment/libs/class/ckditor.class.php.
Affected Software
1 affected component
Wuzhicms Wuzhicms<=4.1.0
Event History
Sep 21, 2021
CVE Published
via MITRE·06:51 PM
Data Sourced
via MITRE·06:51 PM
Description
Frequently Asked Questions
1
What is CVE-2020-19553?
CVE-2020-19553 refers to a Cross Site Scripting (XSS) vulnerability in WUZHI CMS up to and including version 4.1.0.
2
What is the severity of CVE-2020-19553?
CVE-2020-19553 has a severity rating of 5.4, which is considered medium.
3
How does CVE-2020-19553 affect WUZHI CMS?
CVE-2020-19553 allows attackers to inject malicious scripts into the application, potentially leading to unauthorized access or data theft.
4
What is the CWE classification of CVE-2020-19553?
CVE-2020-19553 falls under the CWE classification 79, which refers to Improper Neutralization of Input During Web Page Generation.
5
Is there a fix available for CVE-2020-19553?
Yes, the fix for CVE-2020-19553 is to upgrade WUZHI CMS to version 4.1.1 or later.