ZeroHour

CVE-2020-25470

PoC
CVSS 3.1
6.1 medium
EPSS
1%p70
Published
()
Modified
Description

AntSword 2.1.8.1 contains a cross-site scripting (XSS) vulnerability in the View Site funtion. When viewing an added site, an XSS payload can be injected in cookies view which can lead to remote code execution.

Vendors
antsword project
Products
antsword
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.