← Back

CVE-2020-9012

nvd nist
Published: Feb 16, 2020Modified: Nov 21, 2024

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

A cross-site scripting (XSS) vulnerability in the Import People functionality in Gluu Identity Configuration 4.0 allows remote attackers to inject arbitrary web script or HTML via the filename parameter.

Affected (1)

Products: Gluu: Gluu Server
1 product
Gluu Server
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 4.0

References (2)

Timeline

No history available yet.