ZeroHour

CVE-2020-13870

CVSS 3.1
5.4 medium
EPSS
<1%p44
Published
()
Modified
Description

An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name.

Vendors
verbb
Products
comments
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.