CVE-2020-9028
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow stored XSS via the newUserName parameter on the "User Creation, Deletion and Password Maintenance" screen (when creating a new user).
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.90.70.3 |
| Running on/with | Platform Versions |
|---|---|
Microchip Syncserver S100 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.30 |
| Running on/with | Platform Versions |
|---|---|
Microchip Syncserver S200 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.25 |
| Running on/with | Platform Versions |
|---|---|
Microchip Syncserver S250 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.65.0 |
| Running on/with | Platform Versions |
|---|---|
Microchip Syncserver S300 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.80.1 |
| Running on/with | Platform Versions |
|---|---|
Microchip Syncserver S350 | All versions |
References (2)
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.