CVE-2020-15307: XSS
Published Jun 30, 2020
·Updated
Nozomi Guardian before 19.0.4 allows attackers to achieve stored XSS (in the web front end) by leveraging the ability to create a custom field with a crafted field name.
Affected Software
1 affected component
Nozominetworks Guardian<19.0.4
Event History
Jun 30, 2020
CVE Published
via MITRE·05:50 PM
Data Sourced
via MITRE·05:50 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-15307.
2
What is the severity of CVE-2020-15307?
The severity of CVE-2020-15307 is medium (6.1).
3
How does CVE-2020-15307 impact Nozomi Guardian?
CVE-2020-15307 allows attackers to achieve stored XSS (cross-site scripting) in the web front end of Nozomi Guardian.
4
How can the stored XSS vulnerability in Nozomi Guardian be exploited?
The stored XSS vulnerability in Nozomi Guardian can be exploited by leveraging the ability to create a custom field with a crafted field name.
5
Is there a fix available for CVE-2020-15307?
Yes, a fix is available in Nozomi Guardian version 19.0.4.