CVE-2020-23517
MEDIUM NUCLEIAryanic HighMail <2020 - XSS
Title source: llmDescription
Cross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers to inject arbitrary web script or HTML, via 'user' to LoginForm.
Nuclei Templates (1)
Aryanic HighMail (High CMS) - Cross-Site Scripting
MEDIUMVERIFIEDby geeknik
Shodan:
title:"HighMail" || http.title:"highmail"
FOFA:
title="HighMail" || title="highmail"
Scores
CVSS v3
6.1
EPSS
0.0631
EPSS Percentile
91.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
aryanic/high_cms
< 2020
Published
Mar 26, 2021
Tracked Since
Feb 18, 2026