← Back

CVE-2020-20406

nvd nist
Published: Sep 16, 2020Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

A stored XSS vulnerability exists in the Custom Link Attributes control Affect function in Elementor Page Builder 2.9.2 and earlier versions. It is caused by inadequate filtering on the link custom attributes.

Affected (1)

1 product
Elementor Page Builder
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.9.2

References (2)

Source: cve@mitre.org
ProductThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductThird Party Advisory

Timeline

No history available yet.