Cross-Site Scripting in Croogo CMS by Revolution Systems
CVE-2019-20789
4.8MEDIUM
What is CVE-2019-20789?
Croogo CMS versions prior to 3.0.7 are vulnerable to Cross-Site Scripting (XSS) attacks through the manipulation of the title field in admin menus or taxonomy vocabularies. This flaw allows attackers to embed malicious scripts, which can be executed within the browser of an unsuspecting user, potentially compromising sensitive information or user sessions. Updating to version 3.0.7 or later mitigates this risk.
