Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby injecting arbitrary web script or HTML via modifying the name of the users. The XSS is executed when an administrator access the logs.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2021-04-28 21:15
Updated : 2024-11-21 05:13
NVD link : CVE-2020-22790
Mitre link : CVE-2020-22790
CVE.ORG link : CVE-2020-22790
JSON object : View
Products Affected
safe
- fme_server
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')