Cross Site Scripting Vulnerability in DWSurvey by wkeyuan
CVE-2020-20070

6.1MEDIUM

Key Information:

Vendor

Diaowen

Status
Vendor
CVE Published:
20 June 2023

What is CVE-2020-20070?

A Cross Site Scripting (XSS) vulnerability has been identified in DWSurvey version 1.0 by wkeyuan. This flaw allows remote attackers to craft malicious requests that leverage the 'thequltemld' parameter within the 'qu-multi-fillblank!answers.action' file. When exploited, this vulnerability can enable attackers to execute arbitrary code in the context of the user’s session, potentially leading to unauthorized access and data manipulation. Users of DWSurvey are advised to implement security measures to mitigate the risk related to this vulnerability.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.