Vulnerability Description
Cross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers to inject arbitrary web script or HTML, via 'user' to LoginForm.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aryanic | High Cms | <= 2020 |
Related Weaknesses (CWE)
References
- https://vulnerabilitypublishing.blogspot.com/2021/03/aryanic-highmail-high-cms-rExploitThird Party Advisory
- https://vulnerabilitypublishing.blogspot.com/2021/03/aryanic-highmail-high-cms-rExploitThird Party Advisory
FAQ
What is CVE-2020-23517?
CVE-2020-23517 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers to inject arbitrary web script or HTML, via 'user' to LoginForm.
How severe is CVE-2020-23517?
CVE-2020-23517 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-23517?
Check the references section above for vendor advisories and patch information. Affected products include: Aryanic High Cms.