PT-2021-10694 · Eyoucms · Eyoucms
Published
2021-08-10
·
Updated
2021-08-13
·
CVE-2020-21929
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Eyoucms version 1.4.1
Description:
A stored cross site scripting (XSS) vulnerability in the
web copyright field allows authenticated attackers to execute arbitrary web scripts or HTML. This issue enables attackers to inject malicious code, potentially leading to unauthorized access or control of the affected system.Recommendations:
For Eyoucms version 1.4.1, update the software to a version that fixes the stored XSS vulnerability in the
web copyright field. As a temporary workaround, consider restricting access to the web copyright field to prevent exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eyoucms