Vulnerability Description
A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject arbitrary web script and stolen administrator cookies via the nickname parameter and gain access to the admin panel.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zrlog | Zrlog | 2.1.3 |
Related Weaknesses (CWE)
References
- https://gist.github.com/T-pod/d9405dbd61243990d65d55c5df0fcbe6PatchThird Party Advisory
- https://github.com/94fzb/zrlog/commit/b921c1ae03b8290f438657803eee05226755c941PatchThird Party Advisory
- https://github.com/94fzb/zrlog/issues/56PatchThird Party Advisory
- https://gist.github.com/T-pod/d9405dbd61243990d65d55c5df0fcbe6PatchThird Party Advisory
- https://github.com/94fzb/zrlog/commit/b921c1ae03b8290f438657803eee05226755c941PatchThird Party Advisory
- https://github.com/94fzb/zrlog/issues/56PatchThird Party Advisory
FAQ
What is CVE-2020-21316?
CVE-2020-21316 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject arbitrary web script and stolen administrator cookies via the nickname ...
How severe is CVE-2020-21316?
CVE-2020-21316 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-21316?
Check the references section above for vendor advisories and patch information. Affected products include: Zrlog Zrlog.