Xinuo (formerly SCO) Openserver versions 5 and 6 allows remote attackers to inject arbitrary web script or HTML tag via the parameter 'section' and is vulnerable to reflected cross-site scripting.
id: CVE-2020-25495
info:
name: Xinuo Openserver 5/6 - Cross-Site scripting
author: 0x_Akoko
s
...