First published: Mon Jan 11 2021(Updated: )
XSS exists in JIZHICMS 1.7.1 via index.php/Error/index?msg={XSS] to Home/c/ErrorController.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jizhicms Jizhicms | =1.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-23644 is a vulnerability in JIZHICMS 1.7.1 that allows for cross-site scripting (XSS) attacks.
CVE-2020-23644 affects JIZHICMS 1.7.1 by allowing attackers to execute malicious script code on the affected website.
CVE-2020-23644 has a severity rating of medium with a CVSS score of 6.1.
To fix CVE-2020-23644, it is recommended to update to the latest version of JIZHICMS or apply the provided patch from the official GitHub repository.
More information about CVE-2020-23644 can be found in the reference link: https://github.com/Cherry-toto/jizhicms/issues/28