CVE-2020-25875: XSS
A stored cross site scripting (XSS) vulnerability in the 'Smileys' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payload entered into the 'Smiley Code' parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-25875?
CVE-2020-25875 is a stored cross site scripting (XSS) vulnerability in the Smileys feature of Codoforum v5.0.2.
How does CVE-2020-25875 affect Codoforum?
CVE-2020-25875 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payload entered into the 'Smiley Code' parameter in Codoforum v5.0.2.
What is the severity of CVE-2020-25875?
CVE-2020-25875 has a severity level of medium, with a CVSS score of 5.4.
How can I fix CVE-2020-25875?
To fix CVE-2020-25875, it is recommended to update Codoforum to a version that addresses the vulnerability.
Where can I find more information about CVE-2020-25875?
More information about CVE-2020-25875 can be found on the official Codoforum website and the related GitHub issue.