ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-23370”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-23370
Published
2021-05-10
CVSS:
5.4
ShadowTrackr CVSS:
0.4
Summary:
In YzmCMS 5.6, stored XSS exists via the common/static/plugin/ueditor/1.4.3.3/php/controller.php action parameter, which allows remote attackers to upload a swf file. The swf file can be injected with arbitrary web script or HTML.