CVE-2020-35971: XSS
Published Jun 3, 2021
·Updated
A storage XSS vulnerability is found in YzmCMS v5.8, which can be used by attackers to inject JS code and attack malicious XSS on the /admin/systemmanage/userconfigedit.html page.
Affected Software
1 affected component
YzmCMS YzmCMS=5.8
Event History
Jun 3, 2021
CVE Published
via MITRE·08:55 PM
Data Sourced
via MITRE·08:55 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-35971?
CVE-2020-35971 has been classified as a high-severity vulnerability due to its potential for triggering storage XSS attacks.
2
How do I fix CVE-2020-35971?
To fix CVE-2020-35971, upgrade YzmCMS to version 5.9 or later which addresses this storage XSS vulnerability.
3
What is the impact of CVE-2020-35971?
The impact of CVE-2020-35971 allows attackers to inject malicious JavaScript code that can compromise user data and session integrity.
4
Which versions of YzmCMS are affected by CVE-2020-35971?
CVE-2020-35971 specifically affects YzmCMS version 5.8.
5
Where can I find more information about CVE-2020-35971?
Further information regarding CVE-2020-35971 can be found in the YzmCMS issue tracker.