PT-2020-16093 · Simplephpscripts · Simplephpscripts News Script Php Pro

Published

2020-11-24

·

Updated

2020-11-27

·

CVE-2020-25474

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SimplePHPscripts News Script PHP Pro version 2.3
Description The issue is a Cross Site Scripting (XSS) vulnerability. It can be exploited via the editor name parameter.
Recommendations For SimplePHPscripts News Script PHP Pro version 2.3, avoid using the editor name parameter until the issue is resolved. As a temporary workaround, consider restricting access to the editor name parameter to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25474

Affected Products

Simplephpscripts News Script Php Pro