Feehi CMS 2.0.8 is affected by a cross-site scripting (XSS) vulnerability. When the user name is inserted as JavaScript code, browsing the post will trigger the XSS.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-21146
Reference (s):
- https://github.com/liufee/cms/issues/43

