CVE-2020-20982: XSS
Published Nov 3, 2021
·Updated
Cross Site Scripting (XSS) vulnerability in shadoweb wdja v1.5.1, allows attackers to execute arbitrary code and gain escalated privileges, via the backurl parameter to /php/passport/index.php.
Affected Software
1 affected component
WDJA WDJA CMS=1.5.1
Event History
Nov 3, 2021
CVE Published
via MITRE·04:07 PM
Data Sourced
via MITRE·04:07 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-20982?
The severity of CVE-2020-20982 is critical with a CVSS score of 9.6.
2
What is CVE-2020-20982?
CVE-2020-20982 is a Cross Site Scripting (XSS) vulnerability in shadoweb wdja v1.5.1.
3
How does CVE-2020-20982 work?
CVE-2020-20982 allows attackers to execute arbitrary code and gain escalated privileges via the backurl parameter to /php/passport/index.php.
4
What software versions are affected by CVE-2020-20982?
Wdja Wdja Cms version 1.5.1 is affected by CVE-2020-20982.
5
Is there a fix available for CVE-2020-20982?
There is currently no fix available for CVE-2020-20982. It is recommended to apply any patches or updates provided by the vendor or consider alternative solutions.