CVE-2020-19897: XSS
Published Jun 28, 2022
·Updated
A reflected Cross Site Scripting (XSS) in wuzhicms v4.1.0 allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter.
Affected Software
2 affected components
Wuzhicms Wuzhi Cms=4.1.0
Wuzhicms Wuzhicms=4.1.0
Event History
Jun 28, 2022
CVE Published
via MITRE·09:19 PM
Data Sourced
via MITRE·09:19 PM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-19897?
CVE-2020-19897 is a vulnerability in wuzhicms v4.1.0 that allows remote attackers to execute arbitrary web script or HTML via the imgurl parameter.
2
How severe is CVE-2020-19897?
CVE-2020-19897 has a severity level of 6.1 (medium).
3
How does CVE-2020-19897 affect wuzhicms?
CVE-2020-19897 affects wuzhicms v4.1.0.
4
How can I fix CVE-2020-19897?
To fix CVE-2020-19897, update wuzhicms to a version beyond 4.1.0.
5
Where can I find more information about CVE-2020-19897?
More information about CVE-2020-19897 can be found at the following link: [https://github.com/wuzhicms/wuzhicms/issues/183](https://github.com/wuzhicms/wuzhicms/issues/183)