CVE-2020-19703: XSS
Published Aug 26, 2021
·Updated
A cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Affected Software
1 affected component
dzzoffice DzzOffice=2.02
Event History
Aug 26, 2021
CVE Published
via MITRE·02:22 AM
Data Sourced
via MITRE·02:22 AM
Description
Frequently Asked Questions
1
What is the vulnerability CVE-2020-19703?
CVE-2020-19703 is a cross-site scripting (XSS) vulnerability in the referer parameter of Dzzoffice 2.02.
2
How can an attacker exploit CVE-2020-19703?
Attackers can exploit CVE-2020-19703 by executing arbitrary web scripts or HTML via a crafted payload.
3
What software is affected by CVE-2020-19703?
Dzzoffice 2.02 is affected by CVE-2020-19703.
4
What is the severity of CVE-2020-19703?
CVE-2020-19703 has a severity rating of medium (6.1).
5
Is there a fix for CVE-2020-19703?
A fix for CVE-2020-19703 may be available from the vendor. Check the vendor's website or contact their support for more information.