Vulnerabilities (CVE)

Filtered by vendor Jenkins Subscribe
Filtered by product Vncrecorder
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-2206 1 Jenkins 1 Vncrecorder 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Jenkins VncRecorder Plugin 1.25 and earlier does not escape a parameter value in the checkVncServ form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.
CVE-2020-2205 1 Jenkins 1 Vncrecorder 2024-11-21 3.5 LOW 4.8 MEDIUM
Jenkins VncRecorder Plugin 1.25 and earlier does not escape a tool path in the `checkVncServ` form validation endpoint, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by Jenkins administrators.