ZeroHour

CVE-2020-26046

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p49
Published
()
Modified
Description

FUEL CMS 1.4.11 has stored XSS in Blocks/Navigation/Site variables. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account and also impact other visitors.

Vendors
thedaylightstudio
Products
fuel cms
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.