First published: Fri Dec 18 2020(Updated: )
A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote attackers to inject arbitrary web script or HTML tag via the parameter 'section'.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xinuos OpenServer | =5.0.7 | |
Xinuos OpenServer | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25495 is classified as a reflected Cross-site Scripting (XSS) vulnerability.
To fix CVE-2020-25495, validate and sanitize the 'section' parameter input on the web application.
CVE-2020-25495 affects users of Xinuos OpenServer versions 5.0.7 and 6.0.
Yes, CVE-2020-25495 can be exploited remotely by injecting arbitrary web scripts through the 'section' parameter.
Exploitation of CVE-2020-25495 can lead to the execution of malicious scripts in the context of the user's browser.