Medium severity6.1NVD Advisory· Published Jul 14, 2021· Updated Jun 17, 2026
CVE-2020-29146
CVE-2020-29146
Description
A cross site scripting (XSS) vulnerability in index.php of Wayang-CMS v1.0 allows attackers to execute arbitrary web scripts or HTML via a constructed payload created by adding the X-Forwarded-For field to the header.
Affected products
3- cpe:2.3:a:wayang-cms_project:wayang-cms:1.0:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: =1.0
Patches
Vulnerability mechanics
References
1- lowliness9.me/post/iDACsrRWO/nvdExploitThird Party AdvisoryURL Repurposed
News mentions
0No linked articles in our index yet.