CVE-2020-23371: XSS
Published May 10, 2021
·Updated
Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remote attackers to inject arbitrary web script or HTML via the movieName parameter.
Affected Software
1 affected component
5none Nonecms=1.3.0
Event History
May 10, 2021
CVE Published
via MITRE·10:13 PM
Data Sourced
via MITRE·10:13 PM
Description
Frequently Asked Questions
1
What is CVE-2020-23371?
CVE-2020-23371 is a cross-site scripting (XSS) vulnerability in the static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf file in noneCms v1.3.0.
2
What is the severity of CVE-2020-23371?
The severity of CVE-2020-23371 is classified as medium with a CVSS score of 6.1.
3
How does CVE-2020-23371 affect noneCms?
CVE-2020-23371 affects noneCms version 1.3.0.
4
How can remote attackers exploit CVE-2020-23371?
Remote attackers can exploit CVE-2020-23371 by injecting arbitrary web script or HTML via the movieName parameter in the swfupload.swf file.
5
Is there a fix available for CVE-2020-23371?
To fix CVE-2020-23371, it is recommended to update noneCms to a version that addresses the vulnerability.