Medium severity6.1NVD Advisory· Published Apr 28, 2021· Updated Jun 17, 2026
CVE-2020-18022
CVE-2020-18022
Description
Cross Site Scripting (XSS) in Qibosoft QiboCMS v7 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information by injecting arbitrary commands in a HTTP request to the "ewebeditor\3.1.1\kindeditor.js" component.
Affected products
2- Qibosoft/QiboCMSdescription
Patches
Vulnerability mechanics
References
1- github.com/hpj233/qibocms/blob/master/v7nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.