Description index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS. Remediation References CVE-2020-8825 Related Vulnerabilities Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-42111) Oracle Database Server CVE-2020-2515 Vulnerability (CVE-2020-2515) Squid Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') Vulnerability (CVE-2019-18678) WordPress Other Vulnerability (CVE-2005-1687) WordPress Plugin Wp Cookie Choice Cross-Site Request Forgery (1.1.0) Severity Medium Classification CVE-2020-8825 CWE-707 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities