CVE-2020-20070: Diaowen Dwsurvey

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Cross Site Scripting vulnerability found in wkeyuan DWSurvey 1.0 allows a remote attacker to execute arbitrary code via thequltemld parameter of the qu-multi-fillblank!answers.action file.

Affected products

Published 2023-06-20. Last modified 2026-06-17.