First published: Mon May 10 2021(Updated: )
Cross-site scripting (XSS) vulnerability in static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf in noneCms v1.3.0 allows remote attackers to inject arbitrary web script or HTML via the movieName parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
5none Nonecms | =1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-23371 is a cross-site scripting (XSS) vulnerability in the static/admin/js/kindeditor/plugins/multiimage/images/swfupload.swf file in noneCms v1.3.0.
The severity of CVE-2020-23371 is classified as medium with a CVSS score of 6.1.
CVE-2020-23371 affects noneCms version 1.3.0.
Remote attackers can exploit CVE-2020-23371 by injecting arbitrary web script or HTML via the movieName parameter in the swfupload.swf file.
To fix CVE-2020-23371, it is recommended to update noneCms to a version that addresses the vulnerability.