CVE-2020-19950: XSS
Published Sep 23, 2021
·Updated
A cross-site scripting (XSS) vulnerability in the /banner/add.html component of YzmCMS v5.3 allows attackers to execute arbitrary web scripts or HTML.
Affected Software
1 affected component
YzmCMS YzmCMS=5.3
Event History
Sep 23, 2021
CVE Published
via MITRE·07:46 PM
Data Sourced
via MITRE·07:46 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-19950?
The severity of CVE-2020-19950 is considered to be medium as it allows for cross-site scripting attacks.
2
How do I fix CVE-2020-19950?
To fix CVE-2020-19950, you should upgrade YzmCMS to a version that has patched the XSS vulnerability.
3
What components are affected by CVE-2020-19950?
CVE-2020-19950 affects the /banner/add.html component of YzmCMS version 5.3.
4
What type of attacks does CVE-2020-19950 allow?
CVE-2020-19950 allows attackers to execute arbitrary web scripts or HTML due to the XSS vulnerability.
5
Is CVE-2020-19950 specific to the YzmCMS platform?
Yes, CVE-2020-19950 is specific to the Yzmcms platform version 5.3.