First published: Wed Oct 28 2020(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Citadel WebCit through 926 allow remote attackers to inject arbitrary web script or HTML via multiple pages and parameters. NOTE: this was reported to the vendor in a publicly archived "Multiple Security Vulnerabilities in WebCit 926" thread.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citadel WebCit | <=926 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the multiple cross-site scripting (XSS) vulnerabilities in Citadel WebCit is CVE-2020-27741.
The severity level of CVE-2020-27741 is medium, with a severity value of 6.1.
Remote attackers can exploit CVE-2020-27741 by injecting arbitrary web script or HTML via multiple pages and parameters.
The affected software in CVE-2020-27741 is Citadel WebCit versions up to and including 926.
You can find more information about CVE-2020-27741 in the references provided: http://uncensored.citadel.org/readfwd?go=Citadel%20Security?start_reading_at=4592834 and https://www.citadel.org/