First published: Fri Jun 19 2020(Updated: )
CALDERA 2.7.0 allows XSS via the Operation Name box.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MITRE CALDERA | =2.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14462 is a vulnerability in CALDERA 2.7.0 that allows cross-site scripting (XSS) attacks through the Operation Name box.
CVE-2020-14462 has a severity rating of 5.4, which is considered medium.
CVE-2020-14462 affects CALDERA 2.7.0 by enabling attackers to perform cross-site scripting (XSS) attacks via the Operation Name box.
The CWE ID for CVE-2020-14462 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
Yes, it is recommended to update CALDERA to a version that addresses CVE-2020-14462 to prevent cross-site scripting (XSS) attacks.