CVE-2020-23517

MEDIUM NUCLEI

Aryanic HighMail (High CMS) < 2020 - Cross-Site Scripting via LoginForm User Parameter

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2020-23517 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

Cross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers to inject arbitrary web script or HTML, via 'user' to LoginForm.

Nuclei Templates (1)

Aryanic HighMail (High CMS) - Cross-Site Scripting
MEDIUMVERIFIEDby geeknik
Shodan: title:"HighMail" || http.title:"highmail"
FOFA: title="HighMail" || title="highmail"

References (1)

Core 1
Core References

Scores

CVSS v3 6.1
EPSS 0.0705
EPSS Percentile 93.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
aryanic/high_cms < 2020
Published Mar 26, 2021
Tracked Since Feb 18, 2026