CVE-2020-5620

Cross-site scripting vulnerability in Exment prior to v3.6.0 allows remote authenticated attackers to inject arbitrary script or HTML via a specially crafted file.
References
Link Resource
https://jvn.jp/en/jp/JVN88315581/ Third Party Advisory
https://exment.net/docs/#/weakness/20200819 Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:exceedone:exment:*:*:*:*:*:*:*:*

Information

Published : 2020-08-24 20:15

Updated : 2020-08-25 14:00


NVD link : CVE-2020-5620

Mitre link : CVE-2020-5620


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

exceedone

  • exment