CVE-2020-23517

MEDIUM NUCLEI

Aryanic HighMail <2020 - XSS

Title source: llm

Description

Cross Site Scripting (XSS) vulnerability in Aryanic HighMail (High CMS) versions 2020 and before allows remote attackers to inject arbitrary web script or HTML, via 'user' to LoginForm.

Nuclei Templates (1)

Aryanic HighMail (High CMS) - Cross-Site Scripting
MEDIUMVERIFIEDby geeknik
Shodan: title:"HighMail" || http.title:"highmail"
FOFA: title="HighMail" || title="highmail"

Scores

CVSS v3 6.1
EPSS 0.0631
EPSS Percentile 91.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
aryanic/high_cms < 2020
Published Mar 26, 2021
Tracked Since Feb 18, 2026