vendor:
LeptonCMS
by:
SunCSR (Sun* Cyber Security Research)
6.1
CVSS
MEDIUM
Persistent Cross-Site Scripting
79
CWE
Product Name: LeptonCMS
Affected Version From: 4.5.0
Affected Version To: 4.5.0
Patch Exists: YES
Related CWE: CVE-2020-12707
CPE: a:lepton_cms:lepton_cms
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2020
LeptonCMS 4.5.0 – Persistent Cross-Site Scripting
A stored cross-site-scripting security issue in the edit page feature of LeptonCMS 4.5.0 was discovered. The vulnerable parameter is 'content' and the payload is 'content=<script>alert('XSS')</script>'. The exploit was tested on Windows.
Mitigation:
The vendor released a hotfix and fixed versions to address the issue.