CVE-2020-5620: XSS
Published Aug 25, 2020
·Updated
Cross-site scripting vulnerability in Exment prior to v3.6.0 allows remote authenticated attackers to inject arbitrary script or HTML via a specially crafted file.
Affected Software
1 affected component
exceedone Exment<3.6.0
Event History
Aug 25, 2020
CVE Published
via MITRE·02:20 AM
Data Sourced
via MITRE·02:20 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2020-5620?
CVE-2020-5620 is a cross-site scripting vulnerability in Exment prior to v3.6.0.
2
How does CVE-2020-5620 affect Exment?
CVE-2020-5620 allows remote authenticated attackers to inject arbitrary script or HTML via a specially crafted file.
3
What is the severity of CVE-2020-5620?
CVE-2020-5620 has a severity rating of 5.4, which is considered medium.
4
How do I fix CVE-2020-5620?
To fix CVE-2020-5620, upgrade Exment to version 3.6.0 or higher.
5
Where can I find more information about CVE-2020-5620?
You can find more information about CVE-2020-5620 at the following URLs: [https://exment.net/docs/#/weakness/20200819](https://exment.net/docs/#/weakness/20200819) and [https://jvn.jp/en/jp/JVN88315581/](https://jvn.jp/en/jp/JVN88315581/)