Persistent Cross-site scripting vulnerability on Fork CMS version 5.8.2 allows remote attackers to inject arbitrary Javascript code via the “navigation_title” parameter and the “title” parameter in /private/en/pages/add.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-23263
Reference (s):
- https://github.com/forkcms/forkcms/pull/3093