CVE-2020-19770: XSS
Published Dec 21, 2021
·Updated
A cross-site scripting (XSS) vulnerability in the system bulletin component of WUZHI CMS v4.1.0 allows attackers to steal the admin's cookie.
Affected Software
2 affected components
Wuzhicms Wuzhi Cms=4.1.0
Wuzhicms Wuzhicms=4.1.0
Event History
Dec 21, 2021
CVE Published
via MITRE·05:27 PM
Data Sourced
via MITRE·05:27 PM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-19770?
CVE-2020-19770 is a cross-site scripting (XSS) vulnerability in the system bulletin component of WUZHI CMS v4.1.0.
2
How does CVE-2020-19770 affect WUZHI CMS?
CVE-2020-19770 allows attackers to steal the admin's cookie in WUZHI CMS v4.1.0.
3
What is the severity of CVE-2020-19770?
CVE-2020-19770 has a severity rating of medium (5.4).
4
How can I fix CVE-2020-19770 in WUZHI CMS?
To fix CVE-2020-19770 in WUZHI CMS, you should update to a version higher than v4.1.0.
5
Where can I find more information about CVE-2020-19770?
You can find more information about CVE-2020-19770 at the following reference: https://github.com/wuzhicms/wuzhicms/issues/180