The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.php/dashboard/express/entries/view/ URI.
Dedicated Forum to help removing adware, malware, spyware, ransomware, trojans, viruses and more!
More Stories
CVE-2020-13133 (securechange)
CVE-2020-27256 (anydana-a_firmware, anydana-i_firmware, diabecare_rs_firmware)
CVE-2020-13134 (securechange)