CVE-2020-9007: XSS
Published Feb 16, 2020
·Updated
Codoforum 4.8.8 allows self-XSS via the title of a new topic.
Affected Software
1 affected component
Codologic Codoforum=4.8.8
Event History
Feb 16, 2020
CVE Published
via MITRE·07:08 PM
Data Sourced
via MITRE·07:08 PM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this Codoforum issue?
The vulnerability ID for this Codoforum issue is CVE-2020-9007.
2
What is the severity of CVE-2020-9007?
The severity of CVE-2020-9007 is medium, with a CVSS score of 5.4.
3
How does Codoforum 4.8.8 allow self-XSS?
Codoforum 4.8.8 allows self-XSS by allowing an attacker to insert malicious code in the title of a new topic.
4
How can I fix the CVE-2020-9007 vulnerability?
To fix the CVE-2020-9007 vulnerability, it is recommended to update Codoforum to version 4.8.9 or higher.
5
Where can I find more information about CVE-2020-9007?
More information about CVE-2020-9007 can be found at the following reference: https://github.com/matuhn/Research/blob/master/codoforum/readme.md