CVE-2020-5842: XSS
Published Jan 7, 2020
·Updated
Codoforum 4.8.3 allows XSS in the user registration page: via the username field to the index.php?u=/user/register URI. The payload is, for example, executed on the admin/index.php?page=users/manage page.
Affected Software
1 affected component
Codologic Codoforum=4.8.3
Event History
Jan 7, 2020
CVE Published
via MITRE·07:17 PM
Data Sourced
via MITRE·07:17 PM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-5842?
CVE-2020-5842 is a vulnerability in Codoforum 4.8.3 that allows XSS in the user registration page.
2
How does CVE-2020-5842 work?
CVE-2020-5842 works by exploiting the username field in the user registration page to execute a payload on specific pages.
3
What is the severity of CVE-2020-5842?
The severity of CVE-2020-5842 is medium with a CVSS score of 6.1.
4
Which version of Codoforum is affected by CVE-2020-5842?
Codoforum version 4.8.3 is affected by CVE-2020-5842.
5
How do I fix CVE-2020-5842?
To fix CVE-2020-5842, upgrade Codoforum to a version that is not affected by the vulnerability.