CVE-2020-15339: XSS
Published Jun 26, 2020
·Updated
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 allows live/CPEManager/AXCampaignManager/handlecampaignscriptlink?scriptname= XSS.
Affected Software
2 affected components
Zyxel Cloud CNM SecuManager=3.1.0
Zyxel Cloud CNM SecuManager=3.1.1
Event History
Jun 26, 2020
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
Description
Frequently Asked Questions
1
What is CVE-2020-15339?
CVE-2020-15339 is a vulnerability in Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 that allows XSS via the handle_campaign_script_link API.
2
What is the severity of CVE-2020-15339?
The severity of CVE-2020-15339 is medium with a CVSS score of 6.1.
3
Which software versions are affected by CVE-2020-15339?
Zyxel CloudCNM SecuManager version 3.1.0 and 3.1.1 are affected by CVE-2020-15339.
4
How can the XSS vulnerability be exploited in CVE-2020-15339?
The XSS vulnerability in CVE-2020-15339 can be exploited through the handle_campaign_script_link API.
5
Are there any references for CVE-2020-15339?
Yes, you can find references for CVE-2020-15339 here: [1] and here: [2].