CVE-2020-5305: XSS
Published Jan 5, 2020
·Updated
Codoforum 4.8.3 allows XSS in the admin dashboard via a name field of a new user, i.e., on the Manage Users screen.
Affected Software
1 affected component
Codologic Codoforum=4.8.3
Event History
Jan 5, 2020
CVE Published
via MITRE·10:26 PM
Data Sourced
via MITRE·10:26 PM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-5305.
2
What software versions are affected by CVE-2020-5305?
Codoforum version 4.8.3 is affected by CVE-2020-5305.
3
How severe is CVE-2020-5305?
CVE-2020-5305 has a severity rating of 4.8, which is considered medium.
4
How does CVE-2020-5305 occur?
CVE-2020-5305 occurs when an attacker can inject malicious scripts into the name field of a new user in the admin dashboard of Codoforum 4.8.3.
5
How can I fix CVE-2020-5305?
To fix CVE-2020-5305, it is recommended to update Codoforum to a version that has addressed the vulnerability.