Total
37107 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-5340 | 1 Emc | 1 Rsa Authentication Manager | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When other Security Console administrators attempt to change the default security domain mapping, the injected scripts could potentially be executed in their browser. | |||||
CVE-2020-5339 | 1 Emc | 1 Rsa Authentication Manager | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When other Security Console administrators open the affected report page, the injected scripts could potentially be executed in their browser. | |||||
CVE-2020-5334 | 1 Rsa | 1 Archer | 2024-11-21 | 4.3 MEDIUM | 8.2 HIGH |
RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contains a Document Object Model (DOM) based cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or JavaScript code to DOM environment in the browser. The malicious code is then executed by the web browser in the context of the vulnerable web application. | |||||
CVE-2020-5317 | 1 Dell | 1 Emc Elastic Cloud Storage | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
Dell EMC ECS versions prior to 3.4.0.1 contain an XSS vulnerability. A remote authenticated malicious user could exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application. | |||||
CVE-2020-5308 | 1 Phpgurukul | 1 Dairy Farm Shop Management System | 2024-11-21 | 4.3 MEDIUM | 6.1 MEDIUM |
PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to XSS, as demonstrated by the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName parameter in add-product.php. | |||||
CVE-2020-5306 | 1 Codologic | 1 Codoforum | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
Codoforum 4.8.3 allows XSS via a post using parameters display name, title name, or content. | |||||
CVE-2020-5305 | 1 Codologic | 1 Codoforum | 2024-11-21 | 3.5 LOW | 4.8 MEDIUM |
Codoforum 4.8.3 allows XSS in the admin dashboard via a name field of a new user, i.e., on the Manage Users screen. | |||||
CVE-2020-5298 | 1 Octobercms | 1 October | 2024-11-21 | 3.5 LOW | 4.0 MEDIUM |
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, a user with the ability to use the import functionality of the `ImportExportController` behavior can be socially engineered by an attacker to upload a maliciously crafted CSV file which could result in a reflected XSS attack on the user in question Issue has been patched in Build 466 (v1.0.466). | |||||
CVE-2020-5294 | 1 Prestashop | 1 Prestashop Socialfollow | 2024-11-21 | 3.5 LOW | 4.1 MEDIUM |
PrestaShop module ps_facetedsearch versions before 2.1.0 has a reflected XSS with social networks fields The problem is fixed in 2.1.0 | |||||
CVE-2020-5286 | 1 Prestashop | 1 Prestashop | 2024-11-21 | 4.3 MEDIUM | 4.1 MEDIUM |
In PrestaShop between versions 1.7.4.0 and 1.7.6.5, there is a reflected XSS when uploading a wrong file. The problem is fixed in 1.7.6.5 | |||||
CVE-2020-5285 | 1 Prestashop | 1 Prestashop | 2024-11-21 | 4.3 MEDIUM | 4.1 MEDIUM |
In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is a reflected XSS with `back` parameter. The problem is fixed in 1.7.6.5 | |||||
CVE-2020-5283 | 1 Viewvc | 1 Viewvc | 2024-11-21 | 2.1 LOW | 3.1 LOW |
ViewVC before versions 1.1.28 and 1.2.1 has a XSS vulnerability in CVS show_subdir_lastmod support. The impact of this vulnerability is mitigated by the need for an attacker to have commit privileges to a CVS repository exposed by an otherwise trusted ViewVC instance that also has the `show_subdir_lastmod` feature enabled. The attack vector involves files with unsafe names (names that, when embedded into an HTML stream, would cause the browser to run unwanted code), which themselves can be challenging to create. This vulnerability is patched in versions 1.2.1 and 1.1.28. | |||||
CVE-2020-5278 | 1 Prestashop | 1 Prestashop | 2024-11-21 | 4.3 MEDIUM | 4.1 MEDIUM |
In PrestaShop between versions 1.5.4.0 and 1.7.6.5, there is a reflected XSS on Exception page The problem is fixed in 1.7.6.5 | |||||
CVE-2020-5277 | 1 Prestashop | 1 Faceted Search Module | 2024-11-21 | 3.5 LOW | 4.1 MEDIUM |
PrestaShop module ps_facetedsearch versions before 3.5.0 has a reflected XSS with `url_name` parameter. The problem is fixed in 3.5.0 | |||||
CVE-2020-5276 | 1 Prestashop | 1 Prestashop | 2024-11-21 | 4.3 MEDIUM | 4.1 MEDIUM |
In PrestaShop between versions 1.7.1.0 and 1.7.6.5, there is a reflected XSS on AdminCarts page with `cartBox` parameter The problem is fixed in 1.7.6.5 | |||||
CVE-2020-5273 | 1 Prestashop | 1 Prestashop Linklist | 2024-11-21 | 3.5 LOW | 4.1 MEDIUM |
In PrestaShop module ps_linklist versions before 3.1.0, there is a stored XSS when using custom URLs. The problem is fixed in version 3.1.0 | |||||
CVE-2020-5272 | 1 Prestashop | 1 Prestashop | 2024-11-21 | 4.3 MEDIUM | 4.1 MEDIUM |
In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is a reflected XSS on Search page with `alias` and `search` parameters. The problem is patched in 1.7.6.5 | |||||
CVE-2020-5271 | 1 Prestashop | 1 Prestashop | 2024-11-21 | 4.3 MEDIUM | 4.1 MEDIUM |
In PrestaShop between versions 1.6.0.0 and 1.7.6.5, there is a reflected XSS with `date_from` and `date_to` parameters in the dashboard page This problem is fixed in 1.7.6.5 | |||||
CVE-2020-5269 | 1 Prestashop | 1 Prestashop | 2024-11-21 | 4.3 MEDIUM | 4.1 MEDIUM |
In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminFeatures page by using the `id_feature` parameter. The problem is fixed in 1.7.6.5 | |||||
CVE-2020-5266 | 1 Prestashop | 1 Prestashop Link | 2024-11-21 | 3.5 LOW | 4.4 MEDIUM |
In the ps_link module for PrestaShop before version 3.1.0, there is a stored XSS when you create or edit a link list block with the title field. The problem is fixed in 3.1.0 |