Cross Site Scripting (XSS) in Qibosoft QiboCMS v7 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information by injecting arbitrary commands in a HTTP request to the “ewebeditor3.1.1kindeditor.js” component.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-18022
Reference (s):
- https://github.com/hpj233/qibocms/blob/master/v7

