CVE-2020-23761: XSS
Cross Site Scripting (XSS) vulnerability in subrion CMS Version <= 4.2.1 allows remote attackers to execute arbitrary web script via the "payment gateway" column on transactions tab.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-23761.
What is the severity of CVE-2020-23761?
The severity of CVE-2020-23761 is medium with a CVSS score of 6.1.
What is the affected software?
The affected software is subrion CMS version 4.2.1 and earlier.
How does the vulnerability in subrion CMS Version <= 4.2.1 work?
The vulnerability allows remote attackers to execute arbitrary web scripts by injecting malicious code through the "payment gateway" column on the transactions tab.
Are there any references available for this vulnerability?
Yes, you can find references for this vulnerability at the following URLs: [http://hidden-one.co.in/2021/04/09/cve-2020-23761-stored-xss-vulnerability-in-subrion-cms-version](http://hidden-one.co.in/2021/04/09/cve-2020-23761-stored-xss-vulnerability-in-subrion-cms-version), [https://subrion.org/](https://subrion.org/).