CVE-2020-19949: XSS
Published Sep 23, 2021
·Updated
A cross-site scripting (XSS) vulnerability in the /link/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML.
Affected Software
1 affected component
YzmCMS YzmCMS=5.3
Event History
Sep 23, 2021
CVE Published
via MITRE·07:46 PM
Data Sourced
via MITRE·07:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-19949?
CVE-2020-19949 is classified as a cross-site scripting (XSS) vulnerability that can allow attackers to execute arbitrary scripts in the context of the user.
2
How do I fix CVE-2020-19949?
To mitigate CVE-2020-19949, you should update to a patched version of YzmCMS that addresses this vulnerability.
3
What components are affected by CVE-2020-19949?
CVE-2020-19949 specifically affects the /link/add.html component of YzmCMS version 5.3.
4
Can CVE-2020-19949 be exploited remotely?
Yes, CVE-2020-19949 can be exploited remotely by an attacker through the web application.
5
What impact does CVE-2020-19949 have on users?
CVE-2020-19949 can lead to unauthorized actions on behalf of the user, potentially compromising their data and session.