A stored cross-site scripting (XSS) vulnerability in the getClientIp function in /lib/tinwin.class.php of Chaoji CMS 2.39, allows attackers to execute arbitrary web scripts.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-19962
Reference (s):
- https://github.com/zhuxianjin/vuln_repo/blob/master/chaojicms_stored_xss.md

