Disclosure summary
Potential Abuse on a hooked Function There is a potential for abuse with any plugins that implement the hook function ‘shunt_is_valid_user’. In the code below we simply demonstrate
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
John J Hacking · RSS-d1b0a7c5caf50e2c9e6990076f125380521
Open original source · Updated Oct 23, 2020
CVE-2020-27388: YOURLS 1.5 - 1.7.10, Multiple Stored Cross Site Scripting (XSS) Vulnerabilities in Admin Panel
CVE mention in publisher metadata; check the original affected versions.
Original records & references
- NIST NVD record
- CVE Program record
- johnjhacking.com — Publisher advisory
PUBLISHED 2020-10-23T14:00:00-04:00
MODIFIED 2020-10-23T14:00:00-04:00
INGESTED 2026-10-08T12:10:46-04:00