CVE-2020-20545: XSS
Published Mar 30, 2021
·Updated
Cross-Site Scripting (XSS) vulnerability in Zhiyuan G6 Government Collaboration System V6.1SP1, via the 'method' parameter to 'seeyon/hrSalary.do'.
Affected Software
1 affected component
seeyon G6 Government Collaborative System=6.1-sp1
Event History
Mar 30, 2021
CVE Published
via MITRE·02:17 AM
Data Sourced
via MITRE·02:17 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-20545?
CVE-2020-20545 is classified as a medium-severity Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2020-20545?
To fix CVE-2020-20545, validate and sanitize the 'method' parameter input in the Zhiyuan G6 Government Collaboration System.
3
What is the impact of CVE-2020-20545?
The impact of CVE-2020-20545 allows an attacker to execute arbitrary scripts in a user's browser session.
4
What are the affected versions of the Zhiyuan G6 Government Collaboration System for CVE-2020-20545?
CVE-2020-20545 affects version 6.1 SP1 of the Zhiyuan G6 Government Collaboration System.
5
Is user interaction required to exploit CVE-2020-20545?
Yes, user interaction is typically required for the successful exploitation of CVE-2020-20545.