CVE-2020-26046: XSS
Published Jan 5, 2021
·Updated
FUEL CMS 1.4.11 has stored XSS in Blocks/Navigation/Site variables. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account and also impact other visitors.
Affected Software
1 affected component
TheDayLightStudio Fuel CMS=1.4.11
Event History
Jan 5, 2021
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
Description
Frequently Asked Questions
1
What is CVE-2020-26046?
CVE-2020-26046 is a vulnerability in FUEL CMS 1.4.11 that allows for stored XSS in Blocks/Navigation/Site variables.
2
What is the impact of CVE-2020-26046?
The vulnerability in CVE-2020-26046 can lead to cookie stealing and other malicious actions.
3
How can CVE-2020-26046 be exploited?
CVE-2020-26046 can be exploited by an authenticated account and can also impact other visitors.
4
What is the severity of CVE-2020-26046?
CVE-2020-26046 has a severity rating of medium.
5
How do I fix CVE-2020-26046?
To fix CVE-2020-26046, update to the latest version of FUEL CMS.