PT-2021-10863 · Unknown · Evolution Cms
Luuthehienhbit
·
Published
2021-07-26
·
Updated
2021-07-30
·
CVE-2020-23238
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Evolution CMS version 2.0.2
Description
The issue is a Cross Site Scripting (XSS) vulnerability via the Document Manager feature. This allows for malicious scripts to be injected into the website, potentially leading to unauthorized access or control.
Recommendations
For Evolution CMS version 2.0.2, update to a newer version that contains a fix for this issue, as using the Document Manager feature in this version poses a security risk. As a temporary workaround, consider restricting access to the Document Manager feature until a patch is available.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Evolution Cms