Xinuo (formerly SCO) Openserver versions 5 and 6 allows remote attackers to inject arbitrary web script or HTML tag via the parameter ‘section’ and is vulnerable to reflected cross-site scripting.
View the template here CVE-2020-25495.yaml
References:
https://github.com/ARPSyndicate/cvemon