A cross-site scripting (XSS) vulnerability in the component install\install.sql of Xiuno BBS 4.0.4 allows attackers to execute arbitrary web scripts or HTML via changing the doctype value to 0.
References
Link Resource
https://gitee.com/xiuno/xiunobbs/issues/I16BHH Issue Tracking Third Party Advisory
https://github.com/wanghaiwei/xiuno-docker/issues/4 Exploit Issue Tracking Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-10-04T21:00:36

Updated: 2021-10-04T21:00:36

Reserved: 2020-08-13T00:00:00


Link: CVE-2020-21494

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-10-04T21:15:12.387

Modified: 2021-10-13T20:07:19.207


Link: CVE-2020-21494

JSON object: View

cve-icon Redhat Information

No data.

CWE