CVE-2020-23373: XSS
Published May 10, 2021
·Updated
Cross-site scripting (XSS) vulnerability in admin/nav/add.html in noneCMS v1.3.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the name parameter.
Affected Software
1 affected component
5none Nonecms=1.3.0
Event History
May 10, 2021
CVE Published
via MITRE·10:13 PM
Data Sourced
via MITRE·10:13 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this XSS vulnerability?
The vulnerability ID for this XSS vulnerability is CVE-2020-23373.
2
What is the severity of CVE-2020-23373?
The severity of CVE-2020-23373 is medium.
3
How does the XSS vulnerability CVE-2020-23373 in noneCMS v1.3.0 occur?
The XSS vulnerability CVE-2020-23373 in noneCMS v1.3.0 occurs due to improper input validation of the name parameter in the admin/nav/add.html file.
4
What can an attacker do with this XSS vulnerability in noneCMS v1.3.0?
An attacker with remote authentication can inject arbitrary web script or HTML using the name parameter.
5
Is there a fix for the XSS vulnerability CVE-2020-23373 in noneCMS v1.3.0?
Yes, updating to a version of noneCMS that includes the fix for CVE-2020-23373 will resolve the XSS vulnerability.