CVE-2020-23369: XSS
Published May 10, 2021
·Updated
In YzmCMS 5.6, XSS was discovered in member/membercontent/init.html via the SRC attribute of an IFRAME element because of using UEditor 1.4.3.3.
Affected Software
1 affected component
YzmCMS YzmCMS=5.6
Event History
May 10, 2021
CVE Published
via MITRE·10:14 PM
Data Sourced
via MITRE·10:14 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-23369?
CVE-2020-23369 has been classified with a medium severity level due to its potential for XSS exploitation.
2
How do I fix CVE-2020-23369?
To fix CVE-2020-23369, update YzmCMS to a version that removes the vulnerable UEditor 1.4.3.3 integration.
3
What types of systems are affected by CVE-2020-23369?
CVE-2020-23369 specifically affects YzmCMS version 5.6.
4
What vulnerabilities does CVE-2020-23369 exploit?
CVE-2020-23369 exploits a cross-site scripting (XSS) vulnerability in YzmCMS.
5
Is CVE-2020-23369 likely to be exploited in the wild?
Yes, due to the nature of XSS vulnerabilities, CVE-2020-23369 could potentially be targeted by attackers.