CVE-2020-23370: XSS
Published May 10, 2021
·Updated
In YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which allows remote attackers to upload a swf file. The swf file can be injected with arbitrary web script or HTML.
Affected Software
1 affected component
YzmCMS YzmCMS=5.6
Event History
May 10, 2021
CVE Published
via MITRE·10:14 PM
Data Sourced
via MITRE·10:14 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-23370?
CVE-2020-23370 is classified as a high severity vulnerability due to its potential for injecting malicious scripts.
2
How do I fix CVE-2020-23370?
To fix CVE-2020-23370, upgrade YzmCMS to version 5.7 or later where the vulnerability has been addressed.
3
What type of vulnerability is CVE-2020-23370?
CVE-2020-23370 is a stored cross-site scripting (XSS) vulnerability.
4
What impact does CVE-2020-23370 have on affected systems?
CVE-2020-23370 allows remote attackers to upload malicious SWF files, which can execute arbitrary scripts in users' browsers.
5
Which versions of YzmCMS are affected by CVE-2020-23370?
CVE-2020-23370 affects YzmCMS version 5.6.