CVE-2020-21643

Publication date

2023-04-28 00:00:00

Family

mitre

State

PUBLISHED

Description

Cross Site Scripting (XSS) vulnerability in HongCMS 3.0 allows attackers to run arbitrary code via the callback parameter to /ajax/myshop.