CVE-2020-13870

MEDIUM5.4EPSS 0.21%

Comments plugin stored Cross-site Scripting (XSS) via an asset volume name

Published: 5/24/2022Modified: 4/24/2024
Also known as:GHSA-69ww-wv3j-mhg4

Description

An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References (3)