ZeroHour

CVE-2020-25715

PoC
CVSS 3.1
6.1 medium
EPSS
1%p65
Published
()
Modified
Description

A flaw was found in pki-core 10.9.0. A specially crafted POST request can be used to reflect a DOM-based cross-site scripting (XSS) attack to inject code into the search query form which can get automatically executed. The highest threat from this vulnerability is to data integrity.

Vendors
dogtagpki
Products
dogtagpki
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.