First published: Thu Aug 19 2021(Updated: )
Cross Site Request Forgery (CSRF) vulnerability exists in EyouCMS 1.3.6 that can add an htm page to execute the js code via login.php?m=admin&c=Filemanager&a=newfile&lang=cn.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eyoucms Eyoucms | =1.3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-20642 is classified as high with a severity value of 8.8.
CVE-2020-20642 is a Cross Site Request Forgery (CSRF) vulnerability in EyouCMS version 1.3.6 that allows the execution of JavaScript code via login.php?m=admin&c=Filemanager&a=newfile&lang=cn.
CVE-2020-20642 affects EyouCMS version 1.3.6 by allowing an attacker to add an htm page to execute JavaScript code.
At the moment, there is no known fix for CVE-2020-20642. It is recommended to apply any security patches or updates provided by EyouCMS.
You can find more information about CVE-2020-20642 at the following link: [https://github.com/eyoucms/eyoucms/issues/5](https://github.com/eyoucms/eyoucms/issues/5)