PT-2021-12033 · Pagelayer · Pagelayer
Published
2021-06-07
·
Updated
2021-06-11
·
CVE-2020-36383
CVSS v3.1
6.1
Medium
| Vector | AC:L/AV:N/A:N/C:L/I:L/PR:N/S:C/UI:R |
Name of the Vulnerable Software and Affected Versions:
PageLayer versions prior to 1.3.5
Description:
The issue allows reflected XSS via the
font-size parameter. This can potentially lead to malicious script execution on the client-side.Recommendations:
For versions prior to 1.3.5, update to version 1.3.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the
font-size parameter to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pagelayer