{ "id": "CVE-2020-23647", "sourceIdentifier": "cve@mitre.org", "published": "2023-04-28T20:15:13.320", "lastModified": "2023-04-28T20:15:13.320", "vulnStatus": "Received", "descriptions": [ { "lang": "en", "value": "Cross Site Scripting (XSS) vulnerability in BoxBilling 4.19, 4.19.1, 4.20, and 4.21 allows remote attackers to run arbitrary code via the message field on the submit new ticket form." } ], "metrics": {}, "references": [ { "url": "https://github.com/boxbilling/boxbilling/issues/596", "source": "cve@mitre.org" } ] }