Lucene search

K
cvelistMitreCVELIST:CVE-2020-23370
HistoryMay 10, 2021 - 10:14 p.m.

CVE-2020-23370

2021-05-1022:14:03
mitre
www.cve.org

0.001 Low

EPSS

Percentile

31.2%

In YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which allows remote attackers to upload a swf file. The swf file can be injected with arbitrary web script or HTML.

0.001 Low

EPSS

Percentile

31.2%

Related for CVELIST:CVE-2020-23370