CVE-2020-14014

An issue was discovered in Navigate CMS 2.8 and 2.9 r1433. The query parameter fid on the resource navigate.php does not perform sufficient data validation and/or encoding, making it vulnerable to reflected XSS.
References
Link Resource
https://blog.sean-wright.com/navigate-cms/ Exploit Third Party Advisory
https://cxsecurity.com/issue/WLB-2018090182 Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:naviwebs:navigate_cms:2.8:*:*:*:*:*:*:*
cpe:2.3:a:naviwebs:navigate_cms:2.9:r1433:*:*:*:*:*:*

History

01 May 2022, 01:53

Type Values Removed Values Added
CPE cpe:2.3:a:naviwebs:navigate_cms:2.8:*:*:*:*:*:*:*
References
  • (MISC) https://cxsecurity.com/issue/WLB-2018090182 - Third Party Advisory

06 Aug 2021, 17:15

Type Values Removed Values Added
Summary An issue was discovered in Navigate CMS 2.9 r1433. The query parameter fid on the resource navigate.php does not perform sufficient data validation and/or encoding, making it vulnerable to reflected XSS. An issue was discovered in Navigate CMS 2.8 and 2.9 r1433. The query parameter fid on the resource navigate.php does not perform sufficient data validation and/or encoding, making it vulnerable to reflected XSS.

Information

Published : 2020-06-24 15:15

Updated : 2024-02-04 21:00


NVD link : CVE-2020-14014

Mitre link : CVE-2020-14014

CVE.ORG link : CVE-2020-14014


JSON object : View

Products Affected

naviwebs

  • navigate_cms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')