---
id: CVE-2020-37236
title: >-
  NewsLister contains an authenticated persistent cross-site scripting
  vulnerability that allows authenticated administrators to inject malicious
  scripts through the title parameter in the news addition interface
summary: >-
  NewsLister contains an authenticated persistent cross-site scripting
  vulnerability that allows authenticated administrators to inject malicious
  scripts through the title parameter in the news addition interface. Attackers
  can inject Java…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-05-16'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T10:10:00.263'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-37236'
references:
  - url: 'https://www.exploit-db.com/exploits/49160'
    label: disclosure@vulncheck.com
  - url: 'https://www.netartmedia.net/newslister.html'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/newslister-authenticated-persistent-cross-site-scripting-via-admin-panel
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00235
epssPercentile: 0.12993
ingestedAt: '2026-09-29T10:31:36.285Z'
---

## Overview

NewsLister contains an authenticated persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the title parameter in the news addition interface. Attackers can inject JavaScript payloads via the title field in the admin panel that execute when news items are viewed by other users.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
