CVE-2020-14462: XSS
Published Jun 19, 2020
·Updated
CALDERA 2.7.0 allows XSS via the Operation Name box.
Affected Software
1 affected component
MITRE CALDERA=2.7.0
Event History
Jun 19, 2020
CVE Published
via MITRE·11:34 AM
Data Sourced
via MITRE·11:34 AM
Description
Frequently Asked Questions
1
What is CVE-2020-14462?
CVE-2020-14462 is a vulnerability in CALDERA 2.7.0 that allows cross-site scripting (XSS) attacks through the Operation Name box.
2
How severe is CVE-2020-14462?
CVE-2020-14462 has a severity rating of 5.4, which is considered medium.
3
How does CVE-2020-14462 affect CALDERA 2.7.0?
CVE-2020-14462 affects CALDERA 2.7.0 by enabling attackers to perform cross-site scripting (XSS) attacks via the Operation Name box.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-14462?
The CWE ID for CVE-2020-14462 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
5
Is there a fix available for CVE-2020-14462?
Yes, it is recommended to update CALDERA to a version that addresses CVE-2020-14462 to prevent cross-site scripting (XSS) attacks.