PT-2021-10177 · Bycms · Bycms

Richard1266

·

Published

2021-08-12

·

Updated

2021-08-25

·

CVE-2020-18455

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: bycms version 3.0.4
Description: A Cross Site Scripting (XSS) issue exists due to the lack of proper validation in the title parameter within the edit function in Document.php.
Recommendations: For bycms version 3.0.4, ensure proper validation and sanitization of the title parameter in the edit function of Document.php to prevent XSS attacks.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-18455

Affected Products

Bycms