CVE-2020-22330: XSS
Published Aug 6, 2021
·Updated
Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page.
Affected Software
2 affected componentsFixes available
composer/intelliants/subrion=4.2.1
4.2.2
Intelliants Subrion=4.2.1
Event History
Aug 6, 2021
CVE Published
via MITRE·01:26 PM
Data Sourced
via MITRE·01:26 PM
Description
May 24, 2022
Advisory Published
via GitHub·07:10 PM
Frequently Asked Questions
1
What is CVE-2020-22330?
CVE-2020-22330 is a Cross-Site Scripting (XSS) vulnerability in Subrion 4.2.1 via the title when adding a page.
2
How does CVE-2020-22330 affect Subrion 4.2.1?
CVE-2020-22330 allows an attacker to inject malicious scripts into the title when adding a page in Subrion 4.2.1, leading to potential XSS attacks.
3
What is the severity of CVE-2020-22330?
The severity of CVE-2020-22330 is medium with a CVSS score of 6.1.
4
How can I fix CVE-2020-22330?
To fix CVE-2020-22330, update Subrion to version 4.2.2 or later, as it contains a patch for this vulnerability.
5
Where can I find more information about CVE-2020-22330?
You can find more information about CVE-2020-22330 in the official GitHub issue: https://github.com/intelliants/subrion/issues/850.