CVE-2020-25879: XSS
A stored cross site scripting (XSS) vulnerability in the 'Manage Users' feature of Codoforum v5.0.2 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Username' parameter.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-25879?
CVE-2020-25879 is a stored cross site scripting (XSS) vulnerability in the 'Manage Users' feature of Codoforum v5.0.2.
How does CVE-2020-25879 affect Codoforum?
CVE-2020-25879 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Username' parameter.
What is the severity of CVE-2020-25879?
The severity of CVE-2020-25879 is medium with a CVSS score of 5.4.
How can the stored cross site scripting vulnerability in Codoforum v5.0.2 be exploited?
The stored cross site scripting vulnerability in Codoforum v5.0.2 can be exploited by authenticated attackers who input a crafted payload into the 'Username' parameter.
How can I protect my Codoforum installation from CVE-2020-25879?
To protect your Codoforum installation from CVE-2020-25879, it is recommended to update to a version that includes a fix for the vulnerability.