Record summary

CVE-2020-37236 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.

Description

NewsLister contains an authenticated persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the title parameter in the news addition interface. Attackers can inject JavaScript payloads via the title field in the admin panel that execute when news items are viewed by other users.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 18, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List1.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBNewsLister - Authenticated Persistent Cross-Site ScriptingExploitDB exploitby Emre AslanNot analyzed1 file
ExploitDB

PoC details

References

4