Stored Cross-Site Scripting Vulnerability in BlackCat CMS
CVE-2020-25877
5.4MEDIUM
What is CVE-2020-25877?
A vulnerability exists in the 'Add Page' feature of BlackCat CMS version 1.3.6, where authenticated attackers can exploit a stored cross-site scripting (XSS) flaw. By injecting malicious scripts into the 'Title' parameter, attackers can execute arbitrary web scripts or HTML within the context of the affected application. This issue poses a significant risk as it can lead to unauthorized access and manipulation of web content, highlighting the importance of securing user inputs to prevent such attacks.
