ZeroHour

CVE-2020-21494

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p51
Published
()
Modified
Description

A cross-site scripting (XSS) vulnerability in the component install\install.sql of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via changing the doctype value to 0.

Vendors
xiuno
Products
xiunobbs
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.