CVE-2020-21147: XSS
Published Jan 21, 2021
·Updated
RockOA V1.9.8 is affected by a cross-site scripting (XSS) vulnerability which allows remote attackers to send malicious code to the administrator and execute JavaScript code, because webmain/flow/input/modeemailmAction.php does not perform strict filtering.
Affected Software
1 affected component
Rockoa RockOA=1.9.8
Event History
Jan 21, 2021
CVE Published
via MITRE·08:42 PM
Data Sourced
via MITRE·08:42 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-21147?
The severity of CVE-2020-21147 is rated as medium with a CVSS score of 4.8.
2
How does CVE-2020-21147 impact RockOA V1.9.8?
CVE-2020-21147 impacts RockOA V1.9.8 by allowing remote attackers to send malicious code to the administrator through a cross-site scripting vulnerability.
3
What can remote attackers do with CVE-2020-21147?
Remote attackers can execute JavaScript code by exploiting CVE-2020-21147 in RockOA V1.9.8.