Lucene search

K
cvelistMitreCVELIST:CVE-2020-19002
HistoryAug 27, 2021 - 6:16 p.m.

CVE-2020-19002

2021-08-2718:16:49
mitre
www.cve.org
2
mezzanine v4.3.1
cross site scripting
description field
admin/blog/blogpost/add
cve-2020-19002
remote attackers
execute arbitrary code
cve-2018-16632

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

48.6%

Cross Site Scripting (XSS) in Mezzanine v4.3.1 allows remote attackers to execute arbitrary code via the ‘Description’ field of the component ‘admin/blog/blogpost/add/’. This issue is different than CVE-2018-16632.

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

48.6%

Related for CVELIST:CVE-2020-19002