Arbitrary Code Execution via Cross Site Scripting (XSS) in Maccms10 Background Search Function

Arbitrary Code Execution via Cross Site Scripting (XSS) in Maccms10 Background Search Function

CVE-2020-21362 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

A cross site scripting (XSS) vulnerability in the background search function of Maccms10 allows attackers to execute arbitrary web scripts or HTML via the 'wd' parameter.

Learn more about our Web App Pen Testing.