Vulnerability Description
Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/sites/new.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Craftcms | Craft Cms | 3.1.31 |
Related Weaknesses (CWE)
References
- http://mayoterry.com/file/cve/XSS_vuluerability_in_Craftcms_3.1.31.pdfExploitThird Party Advisory
- https://github.com/craftcms/cms/commit/76a2168b6a5e30144f5c06da4ff264f4eca577ffPatchThird Party Advisory
- http://mayoterry.com/file/cve/XSS_vuluerability_in_Craftcms_3.1.31.pdfExploitThird Party Advisory
- https://github.com/craftcms/cms/commit/76a2168b6a5e30144f5c06da4ff264f4eca577ffPatchThird Party Advisory
FAQ
What is CVE-2020-19626?
CVE-2020-19626 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/sites/new.
How severe is CVE-2020-19626?
CVE-2020-19626 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-19626?
Check the references section above for vendor advisories and patch information. Affected products include: Craftcms Craft Cms.