CVE-2020-17551
Description
ImpressCMS 1.4.0 is affected by XSS in modules/system/admin.php which may result in arbitrary remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
ImpressCMS 1.4.0 has a stored XSS in admin.php that can lead to arbitrary code execution via admin session hijacking.
Vulnerability
Overview
CVE-2020-17551 describes a stored cross-site scripting (XSS) vulnerability in ImpressCMS 1.4.0, specifically within the modules/system/admin.php script. The root cause is insufficient sanitization of user-supplied input in the adsense and customtag modules, allowing an attacker to inject arbitrary JavaScript code that is stored and later executed in the context of an administrator's browser [1][3].
Exploitation
An attacker with the ability to create or edit adsense tags or custom tags can inject a malicious payload into fields such as the adsense ID (adsenseid) or the custom tag name. The vulnerable URLs include /modules/system/admin.php?fct=adsense&op=mod&adsenseid=4 and /modules/system/admin.php?fct=customtag&op=mod. No authentication bypass is required; the attacker must have at least editor-level privileges to access these forms [3].
Impact
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of an authenticated administrator. This can lead to session hijacking, privilege escalation, and potentially arbitrary remote code execution if the attacker leverages the admin session to perform further actions, such as uploading malicious files or modifying system settings [1].
Mitigation
As of the publication date, no official patch has been released for ImpressCMS 1.4.0. Users are advised to upgrade to a supported version (e.g., ImpressCMS 2.0.x) and to apply strict input validation and output encoding as a workaround. The vendor's website provides information on the latest releases [2].
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
impresscms/impresscmsPackagist | < 1.4.1 | 1.4.1 |
Affected products
2- ImpressCMS/ImpressCMSdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/advisories/GHSA-j29g-g982-pwpvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-17551ghsaADVISORY
- github.com/ImpressCMS/impresscms/issues/659ghsax_refsource_MISCWEB
- www.impresscms.orgghsaWEB
- www.impresscms.orgmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.