{"api_version":"1","generated_at":"2026-07-23T15:34:09+00:00","cve":"CVE-2020-21316","urls":{"html":"https://cve.report/CVE-2020-21316","api":"https://cve.report/api/cve/CVE-2020-21316.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-21316","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-21316"},"summary":{"title":"CVE-2020-21316","description":"A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject arbitrary web script and stolen administrator cookies via the nickname parameter and gain access to the admin panel.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-06-15 20:15:00","updated_at":"2021-06-22 01:05:00"},"problem_types":["CWE-79"],"metrics":[],"references":[{"url":"https://github.com/94fzb/zrlog/issues/56","name":"https://github.com/94fzb/zrlog/issues/56","refsource":"MISC","tags":[],"title":"前台文章评论处存储型XSS · Issue #56 · 94fzb/zrlog · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/94fzb/zrlog/commit/b921c1ae03b8290f438657803eee05226755c941","name":"https://github.com/94fzb/zrlog/commit/b921c1ae03b8290f438657803eee05226755c941","refsource":"MISC","tags":[],"title":"Fix #55,#56 xxs inject · 94fzb/zrlog@b921c1a · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"503"},{"url":"https://gist.github.com/T-pod/d9405dbd61243990d65d55c5df0fcbe6","name":"https://gist.github.com/T-pod/d9405dbd61243990d65d55c5df0fcbe6","refsource":"MISC","tags":[],"title":"zrlog-xss.md · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"503"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-21316","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-21316","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"21316","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zrlog","cpe5":"zrlog","cpe6":"2.1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-21316","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject arbitrary web script and stolen administrator cookies via the nickname parameter and gain access to the admin panel."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/94fzb/zrlog/issues/56","refsource":"MISC","name":"https://github.com/94fzb/zrlog/issues/56"},{"url":"https://gist.github.com/T-pod/d9405dbd61243990d65d55c5df0fcbe6","refsource":"MISC","name":"https://gist.github.com/T-pod/d9405dbd61243990d65d55c5df0fcbe6"},{"url":"https://github.com/94fzb/zrlog/commit/b921c1ae03b8290f438657803eee05226755c941","refsource":"MISC","name":"https://github.com/94fzb/zrlog/commit/b921c1ae03b8290f438657803eee05226755c941"}]}},"nvd":{"publishedDate":"2021-06-15 20:15:00","lastModifiedDate":"2021-06-22 01:05:00","problem_types":["CWE-79"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:zrlog:zrlog:2.1.3:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"21316","Ordinal":"182725","Title":"CVE-2020-21316","CVE":"CVE-2020-21316","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"21316","Ordinal":"1","NoteData":"A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject arbitrary web script and stolen administrator cookies via the nickname parameter and gain access to the admin panel.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"21316","Ordinal":"2","NoteData":"2021-06-15","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"21316","Ordinal":"3","NoteData":"2021-06-15","Type":"Other","Title":"Modified"}]}}}