Lucene search

K
osvGoogleOSV:CVE-2020-18035
HistoryApr 29, 2021 - 11:15 p.m.

CVE-2020-18035

2021-04-2923:15:07
Google
osv.dev
2
cve-2020-18035
remote attackers
arbitrary code execution
injection vulnerability
ckeditorfuncnum parameter
ckeditoruploadcontroller.java
jeesns v1.4.2
cross site scripting

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

48.1%

Cross Site Scripting (XSS) in Jeesns v1.4.2 allows remote attackers to execute arbitrary code by injecting commands into the “CKEditorFuncNum” parameter in the component “CkeditorUploadController.java”.

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

48.1%

Related for OSV:CVE-2020-18035