Cross-Site Scripting Vulnerability in Maccms 10 by Maccms
CVE-2020-21387
6.1MEDIUM
What is CVE-2020-21387?
A cross-site scripting (XSS) vulnerability exists in the Maccms 10 product. This flaw enables attackers to inject malicious scripts through the parameter type_en, which can lead to unauthorized access and privilege escalation by obtaining the administrator's cookie. Proper validation and sanitization of user inputs are essential to mitigate this risk. For further technical details, see the issue reported on GitHub.
