CVE-2020-36932

SeaCMS 11.1 contains a stored cross-site scripting vulnerability in the checkuser parameter of the admin settings page. Attackers can inject malicious JavaScript payloads that will execute in users' browsers when the page is loaded.
Configurations

Configuration 1 (hide)

cpe:2.3:a:seacms:seacms:11.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-25 13:15

Updated : 2026-02-02 16:16


NVD link : CVE-2020-36932

Mitre link : CVE-2020-36932

CVE.ORG link : CVE-2020-36932


JSON object : View

Products Affected

seacms

  • seacms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')