CVE-2020-21268: XSS
Published Jun 20, 2023
·Updated
Cross Site Scripting vulnerability in EasySoft ZenTao v.11.6.4 allows a remote attacker to execute arbitrary code via the lastComment parameter.
Affected Software
1 affected component
EasyCorp ZenTao=11.6.4
Event History
Jun 20, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2020-21268?
CVE-2020-21268 is a Cross-Site Scripting (XSS) vulnerability in EasySoft ZenTao v.11.6.4 that allows a remote attacker to execute arbitrary code.
2
How does CVE-2020-21268 affect EasySoft ZenTao v.11.6.4?
CVE-2020-21268 allows a remote attacker to execute arbitrary code in EasySoft ZenTao v.11.6.4 using the lastComment parameter.
3
What is the severity of CVE-2020-21268?
CVE-2020-21268 has a severity rating of medium (6.1).
4
How can I fix CVE-2020-21268?
To fix CVE-2020-21268, it is recommended to update EasySoft ZenTao to a version that includes a patch for the vulnerability.
5
Where can I find more information about CVE-2020-21268?
More information about CVE-2020-21268 can be found at the following link: [https://github.com/easysoft/zentaopms/issues/40]