CVE-2020-27666: XSS
Published Oct 22, 2020
·Updated
Strapi before 3.2.5 has stored XSS in the wysiwyg editor's preview feature.
Affected Software
2 affected componentsFixes available
npm/strapi-plugin-content-manager<3.2.5
3.2.5
Strapi Strapi<3.2.5
Remediation
Patch Available
Event History
Oct 22, 2020
CVE Published
via MITRE·06:19 PM
Data Sourced
via MITRE·06:19 PM
Description
Oct 29, 2020
Advisory Published
07:40 PM
Frequently Asked Questions
1
What is CVE-2020-27666?
CVE-2020-27666 is a vulnerability in Strapi before version 3.2.5 that allows for stored cross-site scripting (XSS) in the wysiwyg editor's preview feature.
2
How severe is CVE-2020-27666?
CVE-2020-27666 has a severity rating of 5.4, which is considered medium.
3
How can I fix CVE-2020-27666?
To fix CVE-2020-27666, update your Strapi installation to version 3.2.5 or later.
4
Where can I find more information about CVE-2020-27666?
You can find more information about CVE-2020-27666 on the NIST National Vulnerability Database (NVD) at https://nvd.nist.gov/vuln/detail/CVE-2020-27666.
5
What is the CWE classification for CVE-2020-27666?
CVE-2020-27666 is classified as CWE-79, which is the code for Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').