Cross-Site Scripting Vulnerability in Macrob7 Macs Framework by vulnerability-lab
CVE-2020-36498

5.4MEDIUM

What is CVE-2020-36498?

The Macrob7 Macs Framework content management system version 1.14f is subject to a cross-site scripting vulnerability located in the account reset function. This security flaw permits attackers to execute arbitrary web scripts or HTML by injecting a crafted payload into the email input field. If exploited, this vulnerability could lead to a range of attacks, compromising user data and the integrity of the web application.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.