{"id":"CVE-2020-23049","details":"Fork CMS Content Management System v5.8.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the `Displayname` field when using the `Add`, `Edit` or `Register' functions. This vulnerability allows attackers to execute arbitrary web scripts or HTML.","aliases":["GHSA-3374-7h99-xr85"],"modified":"2026-07-08T19:02:16.967821Z","published":"2021-10-22T20:15:10.330Z","references":[{"type":"EVIDENCE","url":"https://www.vulnerability-lab.com/get_content.php?id=2208"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/forkcms/forkcms","events":[{"introduced":"f439d630c2f46a85b251488cd7073068a66fae5c"},{"last_affected":"f439d630c2f46a85b251488cd7073068a66fae5c"}],"database_specific":{"cpe":"cpe:2.3:a:fork-cms:fork_cms:5.8.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"5.8.0"},{"last_affected":"5.8.0"}],"source":"CPE_STRING"}}],"versions":["5.8.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-23049.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}