CVE-2020-15183

HIGH

SoyCMS < 3.0.2 - Reflected Cross-Site Scripting Leading to Remote Code Execution

Title source: llm
STIX 2.1

Description

SoyCMS 3.0.2 and earlier is affected by Reflected Cross-Site Scripting (XSS) which leads to Remote Code Execution (RCE) from a known vulnerability. This allows remote attackers to force the administrator to edit files once the adminsitrator loads a specially crafted webpage.

References (3)

Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
https://youtu.be/uAMAwH35ups

Scores

CVSS v3 8.4
EPSS 0.0175
EPSS Percentile 75.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-79
Status published
Products (1)
soycms_project/soycms < 3.0.2
Published Sep 17, 2020
Tracked Since Feb 18, 2026