CVE-2020-35126

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
11/12/2020
Last modified:
04/08/2024

Description

Typesetter CMS 5.x through 5.1 allows admins to conduct Site Title persistent XSS attacks via an Admin/Configuration URI. NOTE: the significance of this report is disputed because "admins are considered trustworthy.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:typesettercms:typesetter:*:*:*:*:*:*:*:* 5.1 (including)


References to Advisories, Solutions, and Tools