Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-23370

In YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which allows remote attackers to upload a swf file. The swf file can be injected with arbitrary web script or HTML.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.3%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2020-23370
  • Yzmcms » Yzmcms » Version: 5.6
    cpe:2.3:a:yzmcms:yzmcms:5.6


Contact Us

Shodan ® - All rights reserved