CVE-2020-25876: XSS
Published Jul 9, 2021
·Updated
A stored cross site scripting (XSS) vulnerability in the 'Pages' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payload entered into the 'Page Title' parameter.
Affected Software
1 affected component
Codologic Codoforum=5.0.2
Event History
Jul 9, 2021
CVE Published
via MITRE·09:56 PM
Data Sourced
via MITRE·09:56 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-25876.
2
What is the severity of CVE-2020-25876?
CVE-2020-25876 has a severity value of 5.4 (Medium).
3
What is the affected software version for CVE-2020-25876?
CVE-2020-25876 affects Codoforum v5.0.2.
4
How does CVE-2020-25876 impact the system?
CVE-2020-25876 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payload in the 'Page Title' parameter.
5
Is there a fix available for CVE-2020-25876?
Yes, upgrading to a version of Codoforum that is not affected by this vulnerability will resolve CVE-2020-25876.