ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-18084”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-18084
Published
2021-04-30
CVSS:
6.1
ShadowTrackr CVSS:
1.2
Summary:
Cross Site Scripting (XSS) in yzmCMS v5.2 allows remote attackers to execute arbitrary code by injecting commands into the "referer" field of a POST request to the component "/member/index/login.html" when logging in.