SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-25470

AntSword 2.1.8.1 contains a cross-site scripting (XSS) vulnerability in the View Site funtion.

MEDIUM 6.1EPSS 1.33%

Does this matter?

Lower severity and a low EPSS score (1.33%). Track it; it rarely justifies an emergency change on its own.

Description

AntSword 2.1.8.1 contains a cross-site scripting (XSS) vulnerability in the View Site funtion. When viewing an added site, an XSS payload can be injected in cookies view which can lead to remote code execution.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
1.33% probability · 69th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
antsword project/antsword
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.