← Back to CVE List

CVE-2020-19885

Published: 2020-08-24T15:15Z
Last Modified: 2024-11-21T05:09Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
DBHcms v1.2.0 has a stored xss vulnerability as there is no htmlspecialchars function for '$_POST['pageparam_insert_name']' variable in dbhcms\mod\mod.page.edit.php line 227, A remote authenticated with admin user can exploit this vulnerability to hijack other users. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt