← Back to CVE List

CVE-2020-18084

Published: 2021-04-30T21:15Z
Last Modified: 2024-11-21T05:08Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Cross Site Scripting (XSS) in yzmCMS v5.2 allows remote attackers to execute arbitrary code by injecting commands into the "referer" field of a POST request to the component "/member/index/login.html" when logging in. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt