CVE-2020-15263
XSS in platform
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8EPSS 0.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
19 Oct 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In platform before version 9.4.4, inline attributes are not properly escaped. If the data that came from users was not escaped, then an XSS vulnerability is possible. The issue was introduced in 9.0.0 and fixed in 9.4.4.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Affected products
orchidsoftware · platformWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →