CVE-2020-26584
The search field "Kurs suchen" on the page Kurskatalog is vulnerable to Reflected XSS.
Does this matter?
Lower severity and a low EPSS score (0.92%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Sage DPW 2020_06_x before 2020_06_002. The search field "Kurs suchen" on the page Kurskatalog is vulnerable to Reflected XSS. If the attacker can lure a user into clicking a crafted link, he can execute arbitrary JavaScript code in the user's browser. The vulnerability can be used to change the contents of the displayed site, redirect to other sites, or steal user credentials. Additionally, users are potential victims of browser exploits and JavaScript malware.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.92% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- sagedpw/sage dpw
- Source
- cve@mitre.org
References
- https://sec-consult.com/en/vulnerability-lab/advisories/Third Party Advisory
- https://seclists.org/fulldisclosure/2020/Oct/17Mailing List, Third Party Advisory
- https://www.sagedpw.atVendor Advisory
- https://sec-consult.com/en/vulnerability-lab/advisories/Third Party Advisory
- https://seclists.org/fulldisclosure/2020/Oct/17Mailing List, Third Party Advisory
- https://www.sagedpw.atVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.