Cross-Site Scripting Vulnerability in bloofoxCMS by Alex Lang
CVE-2020-35761

5.4MEDIUM

Key Information:

Vendor

Bloofox

Vendor
CVE Published:
16 June 2021

What is CVE-2020-35761?

The bloofoxCMS version 0.5.2.1 is susceptible to an XSS vulnerability, which permits remote attackers to inject and execute arbitrary JavaScript or HTML code in the context of a user's session. This can lead to various malicious activities, including session hijacking, data theft, and the distribution of malware. Proper input validation and sanitization measures should be implemented to mitigate this risk. For more details, please refer to the ongoing discussions on the reported issue.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.