SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-15788

A vulnerability has been identified in Polarion Subversion Webclient (All versions).

MEDIUM 6.1EPSS 0.67%

Does this matter?

Lower severity and a low EPSS score (0.67%). Track it; it rarely justifies an emergency change on its own.

Description

A vulnerability has been identified in Polarion Subversion Webclient (All versions). The Polarion subversion web application does not filter user input in a way that prevents Cross-Site Scripting. If a user is enticed into passing specially crafted, malicious input to the web client (e.g. by clicking on a malicious URL with embedded JavaScript), then JavaScript code can be returned and may then be executed by the user’s client. Various actions could be triggered by running malicious JavaScript code.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.67% probability · 50th percentile
CISA KEV
Not listed
Weakness
CWE-80, CWE-79
Affected
siemens/polarion subversion webclient
Source
productcert@siemens.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.