CVE-2020-7051: XSS
Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-5842 because session cookies lack the HttpOnly flag. The impact is account takeover.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-7051?
CVE-2020-7051 is a vulnerability in Codologic Codoforum through version 4.8.4 that allows for stored XSS in the login area.
How does CVE-2020-7051 impact users?
CVE-2020-7051 can lead to account takeover as it allows an attacker to execute malicious code in the login area.
What is the severity of CVE-2020-7051?
CVE-2020-7051 has a severity rating of 6.1, which is considered medium.
How can I fix CVE-2020-7051?
To fix CVE-2020-7051, it is recommended to upgrade Codologic Codoforum to version 4.8.5 or higher, which contains a fix for the vulnerability.
What is the reference for CVE-2020-7051?
The references for CVE-2020-7051 are: [1](https://codologic.com/forum/index.php?u=/topic/12638/codoforum-4-8-8-released-and-the-future#post-23845), [2](https://www.linkedin.com/posts/polina-voronina-896819b5_discovered-by-polina-voronina-jan-15-activity-6634436086540054528-dDgg/)