Vulnerabilities (CVE)

Filtered by CWE-79
Total 37107 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-5340 1 Emc 1 Rsa Authentication Manager 2024-11-21 3.5 LOW 4.8 MEDIUM
RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When other Security Console administrators attempt to change the default security domain mapping, the injected scripts could potentially be executed in their browser.
CVE-2020-5339 1 Emc 1 Rsa Authentication Manager 2024-11-21 3.5 LOW 4.8 MEDIUM
RSA Authentication Manager versions prior to 8.4 P10 contain a stored cross-site scripting vulnerability in the Security Console. A malicious RSA Authentication Manager Security Console administrator with advanced privileges could exploit this vulnerability to store arbitrary HTML or JavaScript code through the Security Console web interface. When other Security Console administrators open the affected report page, the injected scripts could potentially be executed in their browser.
CVE-2020-5334 1 Rsa 1 Archer 2024-11-21 4.3 MEDIUM 8.2 HIGH
RSA Archer, versions prior to 6.7 P2 (6.7.0.2), contains a Document Object Model (DOM) based cross-site scripting vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to supply malicious HTML or JavaScript code to DOM environment in the browser. The malicious code is then executed by the web browser in the context of the vulnerable web application.
CVE-2020-5317 1 Dell 1 Emc Elastic Cloud Storage 2024-11-21 3.5 LOW 4.8 MEDIUM
Dell EMC ECS versions prior to 3.4.0.1 contain an XSS vulnerability. A remote authenticated malicious user could exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When victim users access the data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application.
CVE-2020-5308 1 Phpgurukul 1 Dairy Farm Shop Management System 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to XSS, as demonstrated by the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName parameter in add-product.php.
CVE-2020-5306 1 Codologic 1 Codoforum 2024-11-21 3.5 LOW 4.8 MEDIUM
Codoforum 4.8.3 allows XSS via a post using parameters display name, title name, or content.
CVE-2020-5305 1 Codologic 1 Codoforum 2024-11-21 3.5 LOW 4.8 MEDIUM
Codoforum 4.8.3 allows XSS in the admin dashboard via a name field of a new user, i.e., on the Manage Users screen.
CVE-2020-5298 1 Octobercms 1 October 2024-11-21 3.5 LOW 4.0 MEDIUM
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, a user with the ability to use the import functionality of the `ImportExportController` behavior can be socially engineered by an attacker to upload a maliciously crafted CSV file which could result in a reflected XSS attack on the user in question Issue has been patched in Build 466 (v1.0.466).
CVE-2020-5294 1 Prestashop 1 Prestashop Socialfollow 2024-11-21 3.5 LOW 4.1 MEDIUM
PrestaShop module ps_facetedsearch versions before 2.1.0 has a reflected XSS with social networks fields The problem is fixed in 2.1.0
CVE-2020-5286 1 Prestashop 1 Prestashop 2024-11-21 4.3 MEDIUM 4.1 MEDIUM
In PrestaShop between versions 1.7.4.0 and 1.7.6.5, there is a reflected XSS when uploading a wrong file. The problem is fixed in 1.7.6.5
CVE-2020-5285 1 Prestashop 1 Prestashop 2024-11-21 4.3 MEDIUM 4.1 MEDIUM
In PrestaShop between versions 1.7.6.0 and 1.7.6.5, there is a reflected XSS with `back` parameter. The problem is fixed in 1.7.6.5
CVE-2020-5283 1 Viewvc 1 Viewvc 2024-11-21 2.1 LOW 3.1 LOW
ViewVC before versions 1.1.28 and 1.2.1 has a XSS vulnerability in CVS show_subdir_lastmod support. The impact of this vulnerability is mitigated by the need for an attacker to have commit privileges to a CVS repository exposed by an otherwise trusted ViewVC instance that also has the `show_subdir_lastmod` feature enabled. The attack vector involves files with unsafe names (names that, when embedded into an HTML stream, would cause the browser to run unwanted code), which themselves can be challenging to create. This vulnerability is patched in versions 1.2.1 and 1.1.28.
CVE-2020-5278 1 Prestashop 1 Prestashop 2024-11-21 4.3 MEDIUM 4.1 MEDIUM
In PrestaShop between versions 1.5.4.0 and 1.7.6.5, there is a reflected XSS on Exception page The problem is fixed in 1.7.6.5
CVE-2020-5277 1 Prestashop 1 Faceted Search Module 2024-11-21 3.5 LOW 4.1 MEDIUM
PrestaShop module ps_facetedsearch versions before 3.5.0 has a reflected XSS with `url_name` parameter. The problem is fixed in 3.5.0
CVE-2020-5276 1 Prestashop 1 Prestashop 2024-11-21 4.3 MEDIUM 4.1 MEDIUM
In PrestaShop between versions 1.7.1.0 and 1.7.6.5, there is a reflected XSS on AdminCarts page with `cartBox` parameter The problem is fixed in 1.7.6.5
CVE-2020-5273 1 Prestashop 1 Prestashop Linklist 2024-11-21 3.5 LOW 4.1 MEDIUM
In PrestaShop module ps_linklist versions before 3.1.0, there is a stored XSS when using custom URLs. The problem is fixed in version 3.1.0
CVE-2020-5272 1 Prestashop 1 Prestashop 2024-11-21 4.3 MEDIUM 4.1 MEDIUM
In PrestaShop between versions 1.5.5.0 and 1.7.6.5, there is a reflected XSS on Search page with `alias` and `search` parameters. The problem is patched in 1.7.6.5
CVE-2020-5271 1 Prestashop 1 Prestashop 2024-11-21 4.3 MEDIUM 4.1 MEDIUM
In PrestaShop between versions 1.6.0.0 and 1.7.6.5, there is a reflected XSS with `date_from` and `date_to` parameters in the dashboard page This problem is fixed in 1.7.6.5
CVE-2020-5269 1 Prestashop 1 Prestashop 2024-11-21 4.3 MEDIUM 4.1 MEDIUM
In PrestaShop between versions 1.7.6.1 and 1.7.6.5, there is a reflected XSS on AdminFeatures page by using the `id_feature` parameter. The problem is fixed in 1.7.6.5
CVE-2020-5266 1 Prestashop 1 Prestashop Link 2024-11-21 3.5 LOW 4.4 MEDIUM
In the ps_link module for PrestaShop before version 3.1.0, there is a stored XSS when you create or edit a link list block with the title field. The problem is fixed in 3.1.0