CVE-2020-22392: XSS
Published Aug 5, 2021
·Updated
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file.
Affected Software
1 affected component
Intelliants Subrion CMS=4.2.2
Event History
Aug 5, 2021
CVE Published
via MITRE·09:04 PM
Data Sourced
via MITRE·09:04 PM
Description
Frequently Asked Questions
1
What is CVE-2020-22392?
CVE-2020-22392 is a Cross-Site Scripting (XSS) vulnerability that exists in Subrion CMS version 4.2.2.
2
How does the XSS vulnerability in Subrion CMS 4.2.2 occur?
The XSS vulnerability in Subrion CMS 4.2.2 occurs when adding a blog and then editing an image file.
3
What is the severity of CVE-2020-22392?
CVE-2020-22392 has a severity level of medium with a CVSS score of 5.4.
4
How can I fix the Cross-Site Scripting vulnerability in Subrion CMS 4.2.2?
To fix the Cross-Site Scripting vulnerability in Subrion CMS 4.2.2, update to a newer version of the CMS that includes a patch or workaround for the vulnerability.
5
Where can I find more information about CVE-2020-22392?
You can find more information about CVE-2020-22392 on the official GitHub page of Subrion CMS, specifically in issue #868.