CVE-2020-35240
Summary
| CVE | CVE-2020-35240 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-12-30 15:15:00 UTC |
| Updated | 2022-04-22 18:54:00 UTC |
| Description | FluxBB 1.5.11 is affected by cross-site scripting (XSS in the Blog Content component. This vulnerability can allow an attacker to inject the XSS payload in "Blog Content" and each time any user will visit the blog, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Current stable release - FluxBB | MISC | fluxbb.org | Vendor Advisory |
| CVE-2020-35240: Your example is not reproducible · Issue #1 · hemantsolo/CVE-Reference · GitHub | MISC | github.com | |
| CVE-Reference/CVE-2020-35240.md at main · hemantsolo/CVE-Reference · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.