Description Concrete5 before 8.5.3 does not constrain the sort direction to a valid asc or desc value. Remediation References CVE-2020-14961 Related Vulnerabilities WordPress Plugin Facebook, Twitter & Google+ Social Widgets Multiple Vulnerabilities (1.3.7) WordPress Plugin Simba Plugin Updates Manager Multiple Cross-Site Request Forgery Vulnerabilities (1.6.16) WordPress Plugin SecuPress Free-WordPress Security Security Bypass (1.4.13) Zikula Improper Neutralization of Special Elements used in a Command ('Command Injection') Vulnerability (CVE-2016-9835) Dolibarr Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2015-3935) Severity Medium Classification CVE-2020-14961 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Tags Missing Update Known Vulnerabilities