CVE-2020-19586: XSS
Published Sep 14, 2022
·Updated
Incorrect Access Control issue in Yellowfin Business Intelligence 7.3 allows remote attackers to escalate privilege via MIAdminStyles.i4 Admin UI.
Affected Software
1 affected component
Yellowfinbi Business Intelligence=7.3
Event History
Sep 14, 2022
CVE Published
via MITRE·02:48 AM
Data Sourced
via MITRE·02:48 AM
Description
Frequently Asked Questions
1
What is CVE-2020-19586?
CVE-2020-19586 is an Incorrect Access Control vulnerability in Yellowfin Business Intelligence 7.3, which allows remote attackers to escalate privilege through the MIAdminStyles.i4 Admin UI.
2
What is the severity of CVE-2020-19586?
CVE-2020-19586 has a critical severity with a severity score of 9.
3
How does CVE-2020-19586 affect Yellowfin Business Intelligence?
CVE-2020-19586 affects Yellowfin Business Intelligence version 7.3.
4
How can remote attackers exploit CVE-2020-19586?
Remote attackers can exploit CVE-2020-19586 to escalate their privilege through the MIAdminStyles.i4 Admin UI.
5
Is there a fix available for CVE-2020-19586?
Please refer to the vendor's security advisory or official documentation for information on how to fix CVE-2020-19586.