CVE-2020-23327: XSS
Published Apr 4, 2023
·Updated
Cross Site Scripting vulnerability found in ZblogCN ZblogPHP v.1.0 allows a local attacker to execute arbitrary code via a crafted payload in title parameter of the module management model.
Affected Software
1 affected component
ZblogCN ZblogPHP=1.0
Event History
Apr 4, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-23327?
The severity of CVE-2020-23327 is medium with a severity value of 6.1.
2
How can a local attacker exploit CVE-2020-23327?
A local attacker can exploit CVE-2020-23327 by executing arbitrary code via a crafted payload in the title parameter of the module management model.
3
Which software versions are affected by CVE-2020-23327?
ZblogCN ZblogPHP version 1.0 is affected by CVE-2020-23327.
4
Is there a fix available for CVE-2020-23327?
Currently, there is no available fix for CVE-2020-23327. It is recommended to follow the suggested mitigations provided by the vendor.
5
Where can I find more information about CVE-2020-23327?
You can find more information about CVE-2020-23327 in the official GitHub issue of ZblogCN ZblogPHP: https://github.com/zblogcn/zblogphp/issues/262