Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-9055

Опубликовано: 30 мар. 2020
Источник: nvd
CVSS3: 3.9
CVSS3: 5.4
CVSS2: 3.5
EPSS Низкий

Описание

Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to insert malicious JavaScript that is stored and displayed to the end user. This could lead to website redirects, session cookie hijacking, or information disclosure.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:versiant:lynx_customer_service_portal:3.5.2:*:*:*:*:*:*:*

EPSS

Процентиль: 54%
0.00309
Низкий

3.9 Low

CVSS3

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79
CWE-79

Связанные уязвимости

github
больше 3 лет назад

Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to insert malicious JavaScript that is stored and displayed to the end user. This could lead to website redirects, session cookie hijacking, or information disclosure.

EPSS

Процентиль: 54%
0.00309
Низкий

3.9 Low

CVSS3

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-79
CWE-79