Anchor · Anchor · CVE-2020-12071
**Name of the Vulnerable Software and Affected Versions**
Anchor version 0.12.7
**Description**
The issue allows admins to cause cross-site scripting (XSS) via crafted post content.
**Recommendations**
For Anchor version 0.12.7, consider restricting the ability of admins to post crafted content until a fix is available. As a temporary workaround, avoid using the vulnerable post content feature to minimize the risk of exploitation.