CVE-2020-20391: XSS
Published Jun 23, 2021
·Updated
Cross Site Scripting vulnerability in GetSimpleCMS 3.4.0a in admin/snippets.php via (1) Add Snippet and (2) Save snippets.
Affected Software
1 affected component
Get-simple Getsimplecms=3.4.0-a1
Event History
Jun 23, 2021
CVE Published
via MITRE·02:43 PM
Data Sourced
via MITRE·02:43 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-20391?
The severity of CVE-2020-20391 is medium with a CVSS score of 5.4.
2
How does CVE-2020-20391 affect GetSimpleCMS?
CVE-2020-20391 affects GetSimpleCMS version 3.4.0-a1.
3
What is the Common Weakness Enumeration (CWE) for CVE-2020-20391?
The CWE for CVE-2020-20391 is CWE-79, which is for Cross-Site Scripting (XSS) vulnerabilities.
4
How can I fix CVE-2020-20391 in GetSimpleCMS?
To fix CVE-2020-20391 in GetSimpleCMS, update to a version that is not affected, once a patch or update is available.
5
Where can I find more information about CVE-2020-20391?
You can find more information about CVE-2020-20391 on the GitHub issue page: https://github.com/GetSimpleCMS/GetSimpleCMS/issues/1322