Medium severity4.8NVD Advisory· Published Oct 7, 2020· Updated Jun 17, 2026
CVE-2020-17551
CVE-2020-17551
Description
ImpressCMS 1.4.0 is affected by XSS in modules/system/admin.php which may result in arbitrary remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
impresscms/impresscmsPackagist | < 1.4.1 | 1.4.1 |
Affected products
3cpe:2.3:a:impresscms:impresscms:1.4.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:impresscms:impresscms:1.4.0:*:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
5- github.com/ImpressCMS/impresscms/issues/659nvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-j29g-g982-pwpvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-17551ghsaADVISORY
- www.impresscms.orgghsaWEB
- www.impresscms.orgnvdProduct
News mentions
0No linked articles in our index yet.