PT-2022-8622 · Feehicms · Feehicms
Tazkimi
·
Published
2022-12-15
·
Updated
2025-04-21
·
CVE-2020-20589
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FeehiCMS version 2.0.8
Description
A Cross Site Scripting (XSS) issue allows remote attackers to run arbitrary code via the
lang attribute of an HTML tag. This enables attackers to execute malicious scripts on the client-side, potentially leading to unauthorized actions or data theft.Recommendations
For FeehiCMS version 2.0.8, consider disabling the use of the
lang attribute in HTML tags until a patch is available to prevent exploitation of this issue. Restrict access to areas where this attribute is used to minimize the risk of XSS attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Feehicms