ZeroHour

CVE-2020-23050

PoC
CVSS 3.1
8.0 high
EPSS
1%p65
Published
()
Modified
Description

TAO Open Source Assessment Platform v3.3.0 RC02 was discovered to contain a HTML injection vulnerability in the userFirstName parameter of the user account input field. This vulnerability allows attackers to execute phishing attacks, external redirects, and arbitrary code.

Vendors
taotesting
Products
tao assessment platform
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.