Description Concrete5 before 8.5.3 does not constrain the sort direction to a valid asc or desc value. Remediation References CVE-2020-14961 Related Vulnerabilities WordPress Plugin Absolute Reviews Cross-Site Request Forgery (1.0.8) WordPress Plugin Japanized For WooCommerce Cross-Site Scripting (2.5.4) Django Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-6975) WordPress Plugin WPtouch Open Redirect (3.4.9) WordPress Plugin Tutor LMS-eLearning and online course solution Multiple Cross-Site Scripting Vulnerabilities (1.9.8) Severity Medium Classification CVE-2020-14961 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N Tags Missing Update Known Vulnerabilities