Medium severity4.8NVD Advisory· Published May 14, 2021· Updated Jun 17, 2026
CVE-2020-18167
CVE-2020-18167
Description
Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote attackers to execute arbitrary code by injecting commands into the "Homepage Introduction" field of component "admin/info.php?shuyu".
Affected products
3cpe:2.3:a:laobancms:laobancms:2.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:laobancms:laobancms:2.0:*:*:*:*:*:*:*
- (no CPE)range: =2.0
- LAOBANCMS/LAOBANCMSdescription
Patches
Vulnerability mechanics
References
1- github.com/Cumtyuanfeng/Laobancms/blob/master/vuln.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.