PT-2020-17117 · Lepton · Leptoncms
Sagar Banwa
·
Published
2020-12-02
·
Updated
2020-12-02
·
CVE-2020-29240
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Lepton-CMS version 4.7.0
Description
The issue is related to cross-site scripting (XSS), where an attacker can inject an XSS payload in the URL field of the admin page. This XSS will be triggered each time an admin visits the Menu-Pages-Pages Overview section.
Recommendations
For Lepton-CMS version 4.7.0, as a temporary workaround, consider restricting access to the admin page and the Menu-Pages-Pages Overview section to minimize the risk of exploitation. Avoid using the URL field in the admin page until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Leptoncms