CVE-2020-18693

Cross Site Scripting (XSS) in MineWebCMS v1.7.0 allows remote attackers to execute arbitrary code by injecting malicious code into the 'Title' field of the component '/admin/news'.
References
Link Resource
https://github.com/MineWeb/MineWebCMS/issues/123 Exploit Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:mineweb:minewebcms:1.7.0:*:*:*:*:*:*:*

Information

Published : 2021-08-06 12:15

Updated : 2023-03-03 10:42


NVD link : CVE-2020-18693

Mitre link : CVE-2020-18693


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

mineweb

  • minewebcms