MEDIUM
A stored XSS vulnerability was discovered in Micro Focus Vibe, affecting all Vibe version prior to 4.0.7
Published Mar 25, 2020
5.4
MEDIUMCVSS 3.1
EPSS 0.81%
Description
A stored XSS vulnerability was discovered in Micro Focus Vibe, affecting all Vibe version prior to 4.0.7. The vulnerability could allows a remote attacker to craft and store malicious content into Vibe such that when the content is viewed by another user of the system, attacker controlled JavaScript will execute in the security context of the target user’s browser.
Affected products
-
- Version All Vibe version prior to Vive 4.0.7.StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Micro Focus International | Micro Focus Vibe. | n/a |
|
- < 4.0.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://seclists.org/fulldisclosure/2020/Mar/50 mailing-listx_refsource_FULLDISC
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-30326 Advisory
- https://softwaresupport.softwaregrp.com/doc/KM03630475 x_refsource_MISC
| Link | Providers | Tags |
|---|---|---|
| http://seclists.org/fulldisclosure/2020/Mar/50 | mailing-listx_refsource_FULLDISC | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-30326 | Advisory | |
| https://softwaresupport.softwaregrp.com/doc/KM03630475 | x_refsource_MISC |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner microfocus
Published Mar 25, 2020
Updated Aug 4, 2024
Reserved Mar 1, 2020
Link CVE-2020-9520
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-30326 Assigner microfocus
Published Mar 25, 2020
Updated Aug 4, 2024
Exploited since n/a
Link EUVD-2020-30326