CVE-2020-36607

MEDIUM

FeehiCMS 2.0.8 - XSS

Title source: llm

Description

Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag.

Scores

CVSS v3 6.1
EPSS 0.0018
EPSS Percentile 39.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-79
Status published
Products (2)
feehi/feehicms 2.0.8
feehi/feehicms 0Packagist
Published Dec 15, 2022
Tracked Since Feb 18, 2026