CVE-2020-21316
Summary
| CVE | CVE-2020-21316 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-15 20:15:00 UTC |
| Updated | 2021-06-22 01:05:00 UTC |
| Description | A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject arbitrary web script and stolen administrator cookies via the nickname parameter and gain access to the admin panel. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 前台文章评论处存储型XSS · Issue #56 · 94fzb/zrlog · GitHub | MISC | github.com | |
| Fix #55,#56 xxs inject · 94fzb/zrlog@b921c1a · GitHub | MISC | github.com | |
| zrlog-xss.md · GitHub | MISC | gist.github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.