CVE-2020-13890: XSS
Published Jun 6, 2020
·Updated
The Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard.
Affected Software
1 affected component
Laborator Neon>=2.0<2020-06-03
Event History
Jun 6, 2020
CVE Published
via MITRE·08:02 PM
Data Sourced
via MITRE·08:02 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-13890?
CVE-2020-13890 is considered a medium severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2020-13890?
To fix CVE-2020-13890, update the Neon theme to version 2.0 or later as of June 3, 2020.
3
What software is affected by CVE-2020-13890?
CVE-2020-13890 affects the Neon theme version 2.0 prior to June 3, 2020.
4
What type of vulnerability is CVE-2020-13890?
CVE-2020-13890 is a Cross-Site Scripting (XSS) vulnerability.
5
What can an attacker do with CVE-2020-13890?
An attacker can exploit CVE-2020-13890 to inject malicious scripts into an Add Task Input operation within the dashboard.