Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.
References
Configurations
Information
Published : 2020-08-30 18:15
Updated : 2020-12-04 22:15
NVD link : CVE-2020-24223
Mitre link : CVE-2020-24223
JSON object : View
Products Affected
mara_cms_project
- mara_cms
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
