First published: Thu Jun 03 2021(Updated: )
An issue was discovered in zzcms2020. There is a XSS vulnerability that can insert and execute JS code arbitrarily via /user/manage.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zzcms Zzcms | =2020 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-35973.
The severity of CVE-2020-35973 is medium with a score of 5.4.
The affected software is zzcms 2020 version.
The CWE ID of CVE-2020-35973 is CWE-79.
The XSS vulnerability in CVE-2020-35973 can be exploited by inserting and executing arbitrary JavaScript code via the /user/manage.php page.