Cross Site Scripting Vulnerability in umeditor by Fex Team
CVE-2020-18145
6.1MEDIUM
What is CVE-2020-18145?
A Cross Site Scripting (XSS) vulnerability exists in umeditor version 1.2.3, which can be exploited via the /public/common/umeditor/php/getcontent.php endpoint. This flaw allows attackers to inject malicious scripts into web pages viewed by other users, compromising data integrity and user security. Users of this version of umeditor should evaluate their exposure and apply the necessary patches to mitigate this risk.