← back
CVE-2020-15263

XSS in platform

CVSS 8 HIGHEPSS 0.7%CWE-79
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8EPSS 0.7%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
19 Oct 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In platform before version 9.4.4, inline attributes are not properly escaped. If the data that came from users was not escaped, then an XSS vulnerability is possible. The issue was introduced in 9.0.0 and fixed in 9.4.4.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →