Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby injecting arbitrary web script or HTML via modifying the name of the users. The XSS is executed when an administrator access the logs.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:13
Type | Values Removed | Values Added |
---|---|---|
References | () https://community.safe.com/s/article/FME-Server-Stored-Cross-Site-Scripting-XSS-Vulnerabilities - Vendor Advisory | |
References | () https://community.safe.com/s/article/fme-server-2019-security-update - Vendor Advisory | |
References | () https://mexicanpentester.com/2020/04/09/vulnerabilities-in-fme-server-versions-2019-2-and-2020-0-beta-and-probably-previous-versions/ - Exploit, Third Party Advisory |
Information
Published : 2021-04-28 21:15
Updated : 2024-11-21 05:13
NVD link : CVE-2020-22790
Mitre link : CVE-2020-22790
CVE.ORG link : CVE-2020-22790
JSON object : View
Products Affected
safe
- fme_server
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')