CVE-2013-20006 describes multiple persistent cross-site scripting (XSS) vulnerabilities within the administrative scripts of Qool CMS. Attackers can inject malicious JavaScript via unsanitized POST parameters in various endpoints, leading to arbitrary script execution in administrator browsers. Rated High with a CVSS score of 7.5 (AV:N/AC:L/PR:N/UI:N), this vulnerability has low attack complexity and requires no privileges or user interaction from the attacker, posing a high confidentiality risk. There is no evidence of active exploitation, and public exploit tools like Metasploit or ExploitDB entries are unavailable, indicating very low community attention and exploitability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Qool | Qool CMS | 2.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.