Combodo iTop contains a stored Cross-site Scripting vulnerability, which can be attacked by uploading file with malicious script.
CWE-79
CVE-2020-12718
In administration/comments.php in PHP-Fusion 9.03.50, an authenticated attacker can take advantage of a stored XSS vulnerability in the Preview Comment feature. The protection mechanism can be bypassed by using HTML event handlers such as ontoggle.
CVE-2020-12759
Zulip Server before 2.1.5 allows reflected XSS via the Dropbox webhook.
CVE-2020-12683
Katyshop2 before 2.12 has multiple stored XSS issues.
CVE-2020-12685
XSS in the admin help system admin/help.html and admin/quicklinks.html in Interchange 4.7.0 through 5.11.x allows remote attackers to steal credentials or data via browser JavaScript.
CVE-2020-12696
The iframe plugin before 4.5 for WordPress does not sanitize a URL.
