Cross Site Scripting (CSS) in Wenku CMS v3.4 allows remote attackers to execute arbitrary code via the ‘Intro’ parameter for the component ‘/index.php?m=ucenter&a=index’.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-19157
Reference (s):
- https://github.com/TL-swallow/swallow/issues/14

