CVE-2020-36607: XSS
Published Dec 15, 2022
·Updated
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag.
Affected Software
1 affected component
Feehi Feehicms=2.0.8
Event History
Dec 15, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-36607?
CVE-2020-36607 is classified as a medium severity vulnerability due to its potential for XSS exploitation.
2
How do I fix CVE-2020-36607?
To fix CVE-2020-36607, upgrade FeehiCMS to the latest version that addresses this vulnerability.
3
What is the impact of CVE-2020-36607?
The impact of CVE-2020-36607 allows remote attackers to run arbitrary code on affected sites through XSS.
4
Is CVE-2020-36607 present in versions other than 2.0.8?
No, CVE-2020-36607 specifically affects FeehiCMS version 2.0.8.
5
Can CVE-2020-36607 be exploited in non-web applications?
CVE-2020-36607 is specifically designed for web applications and cannot be exploited in non-web contexts.