Vulnerability Details CVE-2020-23048
SeedDMS Content Management System v6.0.7 contains a persistent cross-site scripting (XSS) vulnerability in the component AddEvent.php via the name and comment parameters.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 55.1%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2020-23048
-
cpe:2.3:a:seeddms:seeddms:4.3.37
-
cpe:2.3:a:seeddms:seeddms:5.0.13
-
cpe:2.3:a:seeddms:seeddms:5.1.14
-
cpe:2.3:a:seeddms:seeddms:5.1.16
-
cpe:2.3:a:seeddms:seeddms:5.1.18
-
cpe:2.3:a:seeddms:seeddms:6.0.7