Symphony · Symphony Cms · CVE-2020-15071
**Name of the Vulnerable Software and Affected Versions**
Symphony CMS version 3.0.0
**Description**
The issue allows for XSS via the `fields['name']` variable to appendSubheading in the content/content.blueprintsevents.php file.
**Recommendations**
For Symphony CMS version 3.0.0, update to a version that includes a fix for this issue, as using the `fields['name']` variable to appendSubheading in the content/content.blueprintsevents.php file poses a security risk.