SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-22790

Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby injecting arbitrary web script or HTML via modifying the name of the users.

MEDIUM 5.4EPSS 1.29%

Does this matter?

Lower severity and a low EPSS score (1.29%). Track it; it rarely justifies an emergency change on its own.

Description

Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby injecting arbitrary web script or HTML via modifying the name of the users. The XSS is executed when an administrator access the logs.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
1.29% probability · 69th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
safe/fme server
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.