CVE-2020-25495: XSS
Published Dec 18, 2020
·Updated
A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote attackers to inject arbitrary web script or HTML tag via the parameter 'section'.
Affected Software
2 affected components
Xinuos Openserver=5.0.7
Xinuos Openserver=6.0
Event History
Dec 18, 2020
CVE Published
via MITRE·02:28 PM
Data Sourced
via MITRE·02:28 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-25495?
CVE-2020-25495 is classified as a reflected Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2020-25495?
To fix CVE-2020-25495, validate and sanitize the 'section' parameter input on the web application.
3
Who is affected by CVE-2020-25495?
CVE-2020-25495 affects users of Xinuos OpenServer versions 5.0.7 and 6.0.
4
Can CVE-2020-25495 be exploited remotely?
Yes, CVE-2020-25495 can be exploited remotely by injecting arbitrary web scripts through the 'section' parameter.
5
What impact does CVE-2020-25495 have on security?
Exploitation of CVE-2020-25495 can lead to the execution of malicious scripts in the context of the user's browser.