CVE-2020-27851: XSS
Published Jan 20, 2021
·Updated
Multiple stored HTML injection vulnerabilities in the "poll" and "quiz" features in an additional paid add-on of Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary HTML code via poll or quiz answers. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).
Affected Software
2 affected componentsFixes available
composer/wp-premium/gravityforms<2.4.21
2.4.21
Rocketgenius Gravityforms Wordpress<2.4.21
Event History
Jan 20, 2021
CVE Published
via MITRE·03:14 AM
Data Sourced
via MITRE·03:14 AM
Description
May 24, 2022
Advisory Published
via GitHub·05:39 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-27851?
CVE-2020-27851 is considered a high severity vulnerability due to the potential for remote HTML injection.
2
How do I fix CVE-2020-27851?
To fix CVE-2020-27851, update the Gravity Forms plugin to version 2.4.21 or later.
3
What software is affected by CVE-2020-27851?
CVE-2020-27851 affects the Gravity Forms plugin version prior to 2.4.21.
4
What type of vulnerabilities are present in CVE-2020-27851?
CVE-2020-27851 contains multiple stored HTML injection vulnerabilities.
5
Can CVE-2020-27851 be exploited by remote attackers?
Yes, CVE-2020-27851 can be exploited by remote attackers to inject arbitrary HTML code.