CVE-2020-14408: XSS
Published Jun 17, 2020
·Updated
An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of arbitrary JavaScript code into a web page's content, creating a Reflected XSS attack vector.
Affected Software
1 affected component
Agentejo Cockpit=0.10.2
Event History
Jun 17, 2020
CVE Published
via MITRE·07:21 PM
Data Sourced
via MITRE·07:21 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-14408.
2
What is the severity of CVE-2020-14408?
The severity of CVE-2020-14408 is medium with a CVSS score of 6.1.
3
What is the affected software version?
The affected software version is Agentejo Cockpit 0.10.2.
4
What is the vulnerability description?
The vulnerability allows for injection of arbitrary JavaScript code into a web page's content, creating a Reflected XSS attack vector.
5
Is there a fix available for this vulnerability?
It is recommended to upgrade to a patched version of Agentejo Cockpit to fix this vulnerability. Please refer to the vendor's advisory or release notes for specific details.