Cross Site Scripting Vulnerability in Evolution CMS by Evolution
CVE-2020-23238

5.4MEDIUM

Key Information:

Vendor

Evo

Vendor
CVE Published:
26 July 2021

What is CVE-2020-23238?

A Cross Site Scripting (XSS) vulnerability has been identified in Evolution CMS version 2.0.2, specifically affecting the Document Manager feature. This vulnerability allows attackers to inject malicious scripts into web pages viewed by other users, potentially compromising user data and session information. Proper input validation and sanitization measures are necessary to mitigate the risks associated with this type of attack.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.