CVE-2020-28845: Critical severity netskope vulnerability
Published Nov 20, 2020
·Updated
A CSV injection vulnerability in the Admin portal for Netskope 75.0 allows an unauthenticated user to inject malicious payload in admin's portal thus leads to compromise admin's system.
Affected Software
1 affected component
Netskope Netskope=75.0
Event History
Nov 20, 2020
CVE Published
via MITRE·07:03 PM
Data Sourced
via MITRE·07:03 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this Netskope CSV injection vulnerability?
The vulnerability ID of this Netskope CSV injection vulnerability is CVE-2020-28845.
2
What is the severity of CVE-2020-28845?
The severity of CVE-2020-28845 is critical with a severity value of 7.8.
3
How does this vulnerability affect Netskope software?
This vulnerability affects Netskope software version 75.0.
4
What is the Common Weakness Enumeration (CWE) ID assigned to this vulnerability?
The Common Weakness Enumeration (CWE) ID assigned to this vulnerability is CWE-1236.
5
Is there a reference for more information about this Netskope CSV injection vulnerability?
Yes, you can find more information about this Netskope CSV injection vulnerability at the following link: http://the-it-wonders.blogspot.com/2020/11/netskope-csv-injection-in-admin-ui.html