First published: Wed Nov 03 2021(Updated: )
Cross Site Scripting (XSS) vulnerability in shadoweb wdja v1.5.1, allows attackers to execute arbitrary code and gain escalated privileges, via the backurl parameter to /php/passport/index.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WHMCS | =1.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-20982 is critical with a CVSS score of 9.6.
CVE-2020-20982 is a Cross Site Scripting (XSS) vulnerability in shadoweb wdja v1.5.1.
CVE-2020-20982 allows attackers to execute arbitrary code and gain escalated privileges via the backurl parameter to /php/passport/index.php.
Wdja Wdja Cms version 1.5.1 is affected by CVE-2020-20982.
There is currently no fix available for CVE-2020-20982. It is recommended to apply any patches or updates provided by the vendor or consider alternative solutions.