CVE-2020-20070: XSS
Published Jun 20, 2023
·Updated
Cross Site Scripting vulnerability found in wkeyuan DWSurvey 1.0 allows a remote attacker to execute arbitrary code via thequltemld parameter of the qu-multi-fillblank!answers.action file.
Affected Software
1 affected component
Diaowen Dwsurvey=1.0
Event History
Jun 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-20070?
CVE-2020-20070 is considered a high severity vulnerability due to its potential for remote code execution through cross-site scripting.
2
How do I fix CVE-2020-20070?
To fix CVE-2020-20070, ensure proper validation and encoding of user input, particularly for the thequltemld parameter in the qu-multi-fillblank!answers.action file.
3
What software is affected by CVE-2020-20070?
CVE-2020-20070 affects DWSurvey version 1.0 by Diaowen.
4
Can CVE-2020-20070 be exploited remotely?
Yes, CVE-2020-20070 can be exploited remotely by attackers to execute arbitrary code.
5
What type of vulnerability is CVE-2020-20070?
CVE-2020-20070 is classified as a Cross Site Scripting (XSS) vulnerability.