CVE-2020-29025 Vulnerability Details

  /     /     /  

CVE-2020-29025 Metadata Quick Info

CVE Published: 16/02/2021 | CVE Updated: 16/09/2024 | CVE Year: 2020
Source: Secomea | Vendor: Secomea | Product: SiteManager Embedded (SM-E)
Status : PUBLISHED

CVE-2020-29025 Description

A vulnerability in SiteManager-Embedded (SM-E) Web server which may allow attacker to construct a URL that if visited by another application user, will cause JavaScript code supplied by the attacker to execute within the user\'s browser in the context of that user\'s session with the application. This issue affects all versions and variants of SM-E prior to version 9.3

Metrics

CVSS Version: 3.1 | Base Score: 5.4 MEDIUM
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* NONE
    User Interaction (UI)* REQUIRED
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* LOW
    Integrity Impact (I)* LOW
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID: CWE-79
CWE Name: CWE-79 Cross-site Scripting (XSS)
Source: Secomea

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).