Cross-Site Scripting Vulnerability in bloofoxCMS by Alex Lang
CVE-2020-35761
5.4MEDIUM
What is CVE-2020-35761?
The bloofoxCMS version 0.5.2.1 is susceptible to an XSS vulnerability, which permits remote attackers to inject and execute arbitrary JavaScript or HTML code in the context of a user's session. This can lead to various malicious activities, including session hijacking, data theft, and the distribution of malware. Proper input validation and sanitization measures should be implemented to mitigate this risk. For more details, please refer to the ongoing discussions on the reported issue.
