Unrated severityNVD Advisory· Published Apr 28, 2021· Updated Aug 4, 2024
CVE-2020-18022
CVE-2020-18022
Description
Cross Site Scripting (XSS) in Qibosoft QiboCMS v7 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information by injecting arbitrary commands in a HTTP request to the "ewebeditor\3.1.1\kindeditor.js" component.
Affected products
2- Qibosoft/QiboCMSdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/hpj233/qibocms/blob/master/v7mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.