Multiple Stored Cross Site Scripting (XSS) vulnerabilities exist in the YOURLS Admin Panel, Versions 1.5 - 1.7.10. An authenticated user must modify a PHP plugin with a malicious payload and upload it, resulting in multiple stored XSS issues. http://yourls.com https://github.com/YOURLS/YOURLS/pull/2761 https://johnjhacking.com/blog/cve-2020-27388/
Created yourls tracking bugs for this issue: Affects: epel-all [bug 1900704] Affects: fedora-all [bug 1900703]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.