Vendor Homepageproduct
http://davidvg.com/ CVE-2020-37111
MEDIUM
60CycleCMS 2.5.2 - 'news.php' Cross-site Scripting (XSS) Vulnerability
Record summary
CVE-2020-37111 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.
Description
60CycleCMS 2.5.2 contains a cross-site scripting (XSS) vulnerability in news.php that allows attackers to inject malicious scripts through GET parameters. Attackers can craft malicious URLs with XSS payloads targeting the 'etsu' and 'ltsu' parameters to execute arbitrary scripts in victim's browsers. This issue does not involve SQL injection.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
60CycleCMSBrowse Davidvg / 60CycleCMS | CVE List | 2.5.2 | affected |
Proofs of concept
1Catalogued exploits
ExploitDB60CycleCMS - 'news.php' SQL InjectionExploitDB exploitby Unkn0wnNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37111 ExploitDB-48177exploit
https://www.exploit-db.com/exploits/48177 Software Download Linkproduct
https://www.opensourcecms.com/60cyclecms VulnCheck Advisory: 60CycleCMS 2.5.2 - 'news.php' Cross-site Scripting (XSS) VulnerabilityThird-party advisory
https://www.vulncheck.com/advisories/cyclecms-newsphp-cross-site-scripting-xss-vulnerability