nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-17362 CVE-2020-17362
MEDIUMNuclei
Nova Lite < 1.3.9 - Cross-Site Scripting
Record summary
CVE-2020-17362 has a selected CVSS score of 6.1 (medium); EIP currently links 1 curated repository PoC and 1 Nuclei template.
Proofs of concept
1Curated repository PoCs
GitHubCVE-2020-17362Curated repository PoCby yubsyStars: 112Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMNova Lite < 1.3.9 - Cross-Site ScriptingCVSS 6.1
Nova Lite before 1.3.9 for WordPress is susceptible to reflected cross-site scripting via search.php.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute malicious scripts in the context of the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Upgrade to Nova Lite version 1.3.9 or later to mitigate this vulnerability.
WeaknessesCWE-79
Authorsdaffainfo
Template tagscve2020cvewordpressxsswp-pluginwpscanunauththemeinprogressvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:themeinprogress:nova_lite:*:*:*:*:*:wordpress:*:*
https://wpscan.com/vulnerability/30a83491-2f59-4c41-98bd-a9e6e5a609d4 https://nvd.nist.gov/vuln/detail/CVE-2020-17362 https://themes.trac.wordpress.org/browser/nova-lite/1.3.9/readme.txt?rev=134076 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
2themes.trac.wordpress.orgConfirmation
https://themes.trac.wordpress.org/browser/nova-lite/1.3.9/readme.txt?rev=134076