CVEs Blog | G5 Cyber Security

CVE-2020-18084 – Cross Site Scripting (XSS) in yzmCMS v5.2 allows remote attackers to exec

Cross Site Scripting (XSS) in yzmCMS v5.2 allows remote attackers to execute arbitrary code by injecting commands into the “referer” field of a POST request to the component “/member/index/login.html” when logging in.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-18084

Reference (s):

Exit mobile version