CVE-2020-19709: XSS
Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a crafted payload.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-19709?
CVE-2020-19709 is classified as a medium severity vulnerability due to its potential for exploitation through arbitrary web or HTML execution.
How do I fix CVE-2020-19709?
To fix CVE-2020-19709, update the Feehi CMS to the latest version that addresses the insufficient filtering of tag parameters.
Who is affected by CVE-2020-19709?
Anyone using Feehi CMS version 0.1.3 is affected by CVE-2020-19709 and should take immediate actions to mitigate the risk.
What can an attacker do with CVE-2020-19709?
An attacker can exploit CVE-2020-19709 to execute arbitrary web or HTML code by crafting a specific payload that bypasses filtering.
Is there a known exploit for CVE-2020-19709?
As of now, while there is no widely reported exploit for CVE-2020-19709, the vulnerability presents a significant risk if left unpatched.