CVE-2020-12261: XSS
Published Apr 28, 2020
·Updated
Open-AudIT 3.3.0 allows an XSS attack after login.
Affected Software
1 affected component
Opmantek Open-AudIT=3.3.0
Event History
Apr 28, 2020
CVE Published
via MITRE·09:12 PM
Data Sourced
via MITRE·09:12 PM
Description
Frequently Asked Questions
1
What is CVE-2020-12261?
CVE-2020-12261 is a vulnerability in Open-AudIT 3.3.0 that allows for a cross-site scripting (XSS) attack after login.
2
What is the severity of CVE-2020-12261?
The severity of CVE-2020-12261 is medium with a CVSS score of 5.4.
3
How does CVE-2020-12261 affect Open-AudIT?
CVE-2020-12261 affects Open-AudIT version 3.3.0.
4
How can I fix CVE-2020-12261?
To fix CVE-2020-12261, it is recommended to upgrade to Open-AudIT version 3.3.1 or later.
5
Where can I find more information about CVE-2020-12261?
More information about CVE-2020-12261 can be found in the references provided: http://packetstormsecurity.com/files/157401/Open-AudIT-3.3.0-Cross-Site-Scripting.html, https://community.opmantek.com/display/OA/Errata+-+3.3.0+XSS+in+error+templates, https://community.opmantek.com/display/OA/Release+Notes+for+Open-AudIT+v3.3.1.