CVE-2020-36932: Seacms 11.1 - 'checkuser' Stored XSS
SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers can inject malicious JavaScript payloads that will execute in users' browsers when the page is loaded.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36932?
CVE-2020-36932 is classified as a medium severity vulnerability due to the potential for stored cross-site scripting attacks.
How do I fix CVE-2020-36932?
To fix CVE-2020-36932, it is recommended to sanitize user inputs on the admin settings page and apply security patches from SeaCMS.
Who is affected by CVE-2020-36932?
CVE-2020-36932 affects SeaCMS version 11.1 specifically in the admin settings checkuser parameter.
What types of attacks can exploit CVE-2020-36932?
CVE-2020-36932 can be exploited by attackers to inject malicious JavaScript that executes in users' browsers.
What should I do if I suspect an exploit of CVE-2020-36932?
If you suspect an exploit of CVE-2020-36932, immediately review your logs, update to the latest version of SeaCMS, and implement proper input validation controls.