← Back to CVE List

CVE-2020-29240

Published: 2020-12-02T17:15Z
Last Modified: 2024-11-21T05:23Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Lepton-CMS 4.7.0 is affected by cross-site scripting (XSS). An attacker can inject the XSS payload in the URL field of the admin page and each time an admin visits the Menu-Pages-Pages Overview section, the XSS will be triggered. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt