CVE-2020-22394: XSS
Published Nov 19, 2020
·Updated
In YzmCMS v5.5 the member contribution function in the editor contains a cross-site scripting (XSS) vulnerability.
Affected Software
1 affected component
YzmCMS YzmCMS=5.5
Event History
Nov 19, 2020
CVE Published
via MITRE·05:55 PM
Data Sourced
via MITRE·05:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-22394?
CVE-2020-22394 is classified as a cross-site scripting (XSS) vulnerability, which can lead to data exposure or application compromise.
2
How do I fix CVE-2020-22394?
To remediate CVE-2020-22394, ensure that user inputs in the member contribution function are properly sanitized to prevent XSS attacks.
3
Which versions of Yzmcms are affected by CVE-2020-22394?
CVE-2020-22394 specifically affects Yzmcms version 5.5.
4
What type of vulnerability is CVE-2020-22394?
CVE-2020-22394 is a cross-site scripting (XSS) vulnerability found in the member contribution function of Yzmcms.
5
What consequences can arise from CVE-2020-22394?
Exploitation of CVE-2020-22394 could allow attackers to run malicious scripts in the context of a victim's browser, potentially leading to unauthorized actions or data theft.