CVE-2020-27388: XSS
Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An authenticated user must modify a PHP plugin with a malicious payload and upload it, resulting in multiple stored XSS issues.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/yourls/yourlsto a version that resolves this vulnerability.Fixed in 1.8
Event History
Frequently Asked Questions
What is CVE-2020-27388?
CVE-2020-27388 is a vulnerability that allows an authenticated user to upload a PHP plugin with a malicious payload, resulting in multiple stored Cross Site Scripting (XSS) issues in the YOURLS Admin Panel versions 1.5 - 1.7.10.
How severe is CVE-2020-27388?
CVE-2020-27388 has a severity score of 5.4, which is classified as medium severity.
What is the affected software for CVE-2020-27388?
The affected software for CVE-2020-27388 is YOURLS Admin Panel versions 1.5 - 1.7.10.
How can an attacker exploit CVE-2020-27388?
An attacker can exploit CVE-2020-27388 by modifying a PHP plugin with a malicious payload and uploading it to the YOURLS Admin Panel.
Are there any references for CVE-2020-27388?
Yes, you can find references for CVE-2020-27388 at the following links: http://yourls.com, https://github.com/YOURLS/YOURLS/pull/2761, https://johnjhacking.com/blog/cve-2020-27388/