Stored Cross Site Scripting Vulnerability in YOURLS by YOURLS
CVE-2020-27388

5.4MEDIUM

Key Information:

Vendor

Yourls

Status
Vendor
CVE Published:
23 October 2020

What is CVE-2020-27388?

Multiple Stored Cross Site Scripting (XSS) vulnerabilities have been identified in the YOURLS Admin Panel, affecting versions 1.5 to 1.7.10. An authenticated user can exploit these vulnerabilities by modifying a PHP plugin with a malicious payload and uploading it to the Admin Panel. This can lead to various security risks, including unauthorized access to sensitive data and further exploits within the application.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.