CVE-2020-23341: XSS
Published Aug 17, 2021
·Updated
A reflected cross site scripting (XSS) vulnerability in the /header.tmpl.php component of ATutor 2.2.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Affected Software
1 affected component
ATutor ATutor<=2.2.4
Event History
Aug 17, 2021
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-23341?
CVE-2020-23341 is classified as a high severity reflected cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2020-23341?
To fix CVE-2020-23341, upgrade to a version of ATutor later than 2.2.4 that addresses this vulnerability.
3
What is CVE-2020-23341?
CVE-2020-23341 is a reflected cross-site scripting (XSS) vulnerability in the /header.tmpl.php component of ATutor allowing execution of arbitrary scripts.
4
What versions of ATutor are affected by CVE-2020-23341?
CVE-2020-23341 affects ATutor versions up to and including 2.2.4.
5
How can attackers exploit CVE-2020-23341?
Attackers can exploit CVE-2020-23341 by sending a crafted payload via URL parameters to execute arbitrary web scripts or HTML.