Description
Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-5842 because session cookies lack the HttpOnly flag. The impact is account takeover.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-28185 | Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-5842 because session cookies lack the HttpOnly flag. The impact is account takeover. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T09:18:02.831Z
Reserved: 2020-01-14T00:00:00.000Z
Link: CVE-2020-7051
No data.
Status : Modified
Published: 2020-02-13T16:15:13.807
Modified: 2024-11-21T05:36:34.063
Link: CVE-2020-7051
No data.
OpenCVE Enrichment
No data.
EUVD