CVE-2020-26517: XSS
A cross-site scripting (XSS) issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. It is possible to perform XSS attacks through using the WebDAV functionality to upload files to a project (Authn users), using the users import functionality (Admin only), and changing the login text in the application configuration (Admin only).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26517?
CVE-2020-26517 has a moderate severity level due to its potential for cross-site scripting attacks.
How do I fix CVE-2020-26517?
To fix CVE-2020-26517, upgrade to a patched version of Intland codeBeamer ALM, specifically version 10.1.SP5 or higher.
What are the affected versions of CVE-2020-26517?
CVE-2020-26517 affects Intland codeBeamer ALM versions 10.0.0 through 10.1.0.SP4.
What type of attack is possible with CVE-2020-26517?
CVE-2020-26517 allows for cross-site scripting (XSS) attacks through vulnerable WebDAV functionalities.
Who is affected by CVE-2020-26517?
Authenticated users and admin users of Intland codeBeamer ALM are affected by CVE-2020-26517.