PT-2020-15666 · Mara · Mara Cms
George Tsimpidas
·
Published
2020-08-30
·
Updated
2022-11-08
·
CVE-2020-24223
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Mara CMS version 7.5
Description
The issue allows cross-site scripting (XSS) in contact.php via the
theme or pagetheme parameters. This means an attacker could potentially inject malicious scripts into the website, affecting users who visit the compromised page.Recommendations
For Mara CMS version 7.5, as a temporary workaround, consider restricting access to the contact.php page or disabling the
theme and pagetheme parameters until a patch is available. Avoid using the theme and pagetheme parameters in the affected contact.php page until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mara Cms