VulnerabilityModified
CVE-2020-13870
There is stored XSS via an asset volume name.
MEDIUM 5.4EPSS 0.54%
Does this matter?
Lower severity and a low EPSS score (0.54%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.54% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- verbb/comments
- Source
- cve@mitre.org
References
- https://github.com/verbb/comments/blob/craft-3/CHANGELOG.md#155---2020-05-28-criticalRelease Notes, Third Party Advisory
- https://github.com/verbb/comments/blob/craft-3/CHANGELOG.md#155---2020-05-28-criticalRelease Notes, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.