Lucene search

K
prionPRIOn knowledge basePRION:CVE-2020-23370
HistoryMay 10, 2021 - 11:15 p.m.

Cross site scripting

2021-05-1023:15:00
PRIOn knowledge base
www.prio-n.com
2

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.2%

In YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which allows remote attackers to upload a swf file. The swf file can be injected with arbitrary web script or HTML.

CPENameOperatorVersion
yzmcmseq5.6

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.2%

Related for PRION:CVE-2020-23370