CVE-2020-21146: XSS
Published Jan 21, 2021
·Updated
Feehi CMS 2.0.8 is affected by a cross-site scripting (XSS) vulnerability. When the user name is inserted as JavaScript code, browsing the post will trigger the XSS.
Affected Software
2 affected componentsFixes available
composer/feehi/cms<=2.0.8
2.0.8.1
Feehi Feehi CMS=2.0.8
Event History
Jan 21, 2021
CVE Published
via MITRE·08:42 PM
Data Sourced
via MITRE·08:42 PM
Description
May 24, 2022
Advisory Published
05:40 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-21146?
CVE-2020-21146 has a medium severity level due to its potential impact on user data security.
2
How do I fix CVE-2020-21146?
To fix CVE-2020-21146, upgrade Feehi CMS to version 2.0.8.1 or later, as this version addresses the vulnerability.
3
What type of vulnerability is CVE-2020-21146?
CVE-2020-21146 is a cross-site scripting (XSS) vulnerability affecting Feehi CMS.
4
Who is affected by CVE-2020-21146?
Users of Feehi CMS versions up to 2.0.8 are vulnerable to CVE-2020-21146.
5
What can attackers do with CVE-2020-21146?
Attackers can exploit CVE-2020-21146 to execute arbitrary JavaScript code in the browser of users viewing affected posts.