
Cloud Vulnerability DB
A community-led vulnerabilities database
Fork CMS before version 5.8.3 contained a Cross-Site Scripting (XSS) vulnerability that allowed attackers to inject malicious JavaScript code via the navigation_title or title parameters. The vulnerability was discovered and disclosed on May 27, 2020 (CISA Bulletin, MITRE).
The vulnerability existed due to insufficient input validation of the navigation_title and title fields in the content management system. This allowed HTML with embedded JavaScript to be injected and executed in both the frontend and backend interfaces. The vulnerability was assigned a CVSS score of 4.3, indicating medium severity (CISA Bulletin).
Successful exploitation of this vulnerability could allow attackers to execute arbitrary JavaScript code in the context of other users' browsers, potentially leading to theft of sensitive information, session hijacking, or other malicious actions (GitHub PR).
The vulnerability could be exploited by an attacker who has access to create or modify content in the CMS, specifically through the navigation_title or title fields (GitHub PR).
The vulnerability was fixed in Fork CMS version 5.8.3 by implementing proper input validation that allows HTML but strips out JavaScript content. Users should upgrade to version 5.8.3 or later to protect against this vulnerability (GitHub PR).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."