CVE-2020-27852: XSS
A stored Cross-Site Scripting (XSS) vulnerability in the survey feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via a textarea field. This code is interpreted by users in a privileged role (Administrator, Editor, etc.).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-27852?
CVE-2020-27852 has a high severity rating due to its potential for stored Cross-Site Scripting attacks.
How do I fix CVE-2020-27852?
To fix CVE-2020-27852, update the Gravity Forms plugin to version 2.4.21 or later.
Who is affected by CVE-2020-27852?
CVE-2020-27852 affects users of Gravity Forms versions prior to 2.4.21 with vulnerable installations.
What impact can CVE-2020-27852 have on users?
CVE-2020-27852 can allow attackers to inject malicious scripts that may affect users with privileged roles.
Is CVE-2020-27852 a common vulnerability?
CVE-2020-27852 is a known vulnerability within the Gravity Forms plugin, making it critical for users to address.