ZeroHour

CVE-2020-23517

PoC
CVSS 3.1
6.1 medium
EPSS
7%p94
Published
()
Modified
Description

Cross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers to inject arbitrary web script or HTML, via 'user' to LoginForm.

Vendors
aryanic
Products
high cms
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.