CVE-2020-37111 | Davidvg 60CycleCMS 2.5.2 GET Parameter news.php etsu/ltsu cross site scripting (Exploit 48177 / EUVD-2020-30984)
A vulnerability described as problematic has been identified in Davidvg 60CycleCMS 2.5.2. Affected by this issue is some unknown functionality of the file news.php of the component GET Parameter Handler. Such manipulation of the argument etsu/ltsu leads to cross site scripting.
This vulnerability is listed as CVE-2020-37111. The attack may be performed from remote. In addition, an exploit is available.