CVE-2020-21316: Zrlog
Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.
A Cross-site scripting (XSS) vulnerability exists in the comment section in ZrLog 2.1.3, which allows remote attackers to inject arbitrary web script and stolen administrator cookies via the nickname parameter and gain access to the admin panel.
Affected products
- Zrlog Zrlog: version 2.1.3 only
Published 2021-06-15. Last modified 2026-06-17.