PT-2022-8622 · Feehicms · Feehicms

Tazkimi

·

Published

2022-12-15

·

Updated

2025-04-21

·

CVE-2020-20589

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions FeehiCMS version 2.0.8
Description A Cross Site Scripting (XSS) issue allows remote attackers to run arbitrary code via the lang attribute of an HTML tag. This enables attackers to execute malicious scripts on the client-side, potentially leading to unauthorized actions or data theft.
Recommendations For FeehiCMS version 2.0.8, consider disabling the use of the lang attribute in HTML tags until a patch is available to prevent exploitation of this issue. Restrict access to areas where this attribute is used to minimize the risk of XSS attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-20589
GHSA-PWH3-3PCM-6VJH

Affected Products

Feehicms