Vulnerability Description
An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4.
CVSS Score
5.4
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Appsbd | Best Support System | 3.0.4 |
Related Weaknesses (CWE)
References
- https://ex-mi.ru/exploit/%5B2020-08-23%5D-%5BPHP%5D-best-support-system-v3.0.4.t
- https://medium.com/%40ex.mi/php-best-support-system-v3-0-4-authenticated-persist
- https://ex-mi.ru/exploit/%5B2020-08-23%5D-%5BPHP%5D-best-support-system-v3.0.4.t
- https://medium.com/%40ex.mi/php-best-support-system-v3-0-4-authenticated-persist
FAQ
What is CVE-2020-24963?
CVE-2020-24963 is a vulnerability with a CVSS score of 5.4 (MEDIUM). An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4.
How severe is CVE-2020-24963?
CVE-2020-24963 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-24963?
Check the references section above for vendor advisories and patch information. Affected products include: Appsbd Best Support System.