Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-26884

Опубликовано: 18 нояб. 2020
Источник: nvd
CVSS3: 6.1
CVSS2: 4.3
EPSS Низкий

Описание

RSA Archer 6.8 through 6.8.0.3 and 6.9 contains a URL injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user into executing malicious JavaScript code in the context of the web application.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:rsa:archer:*:*:*:*:*:*:*:*
Версия от 6.8 (включая) до 6.8.0.3 (включая)
cpe:2.3:a:rsa:archer:6.9:*:*:*:*:*:*:*

EPSS

Процентиль: 64%
0.00469
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-74

Связанные уязвимости

github
больше 3 лет назад

RSA Archer 6.8 through 6.8.0.3 and 6.9 contains a URL injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user into executing malicious JavaScript code in the context of the web application.

EPSS

Процентиль: 64%
0.00469
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-74