CVE-2020-18165
PoC —CVSS 3.1
4.8 medium
EPSS
<1%p58
Published
()
Modified
Description
Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands into the "Website SEO Keywords" field on the page "admin/info.php?shuyu".
- Vendors
- laobancms
- Products
- laobancms
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.