PT-2021-10872 · Fork Cms · Fork Cms

Carakas

·

Published

2021-05-06

·

Updated

2022-02-10

·

CVE-2020-23263

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Fork CMS version 5.8.2
Description The issue allows remote attackers to inject arbitrary Javascript code via the navigation title parameter and the title parameter in the "/private/en/pages/add" endpoint. This enables attackers to execute malicious scripts on the client-side.
Recommendations For Fork CMS version 5.8.2, consider disabling the navigation title and title parameters in the "/private/en/pages/add" endpoint until a patch is available. Restrict access to this endpoint to minimize the risk of exploitation. Avoid using the navigation title and title parameters in the affected endpoint until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-23263
GHSA-VP4X-94FF-2CMV

Affected Products

Fork Cms