CVE-2020-28930: XSS
A Cross-Site Scripting (XSS) issue in the 'update user' and 'delete user' functionalities in settings/users.php in EPSON EPS TSE Server 8 (21.0.11) allows an authenticated attacker to inject a JavaScript payload in the user management page that is executed by an administrator.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-28930?
CVE-2020-28930 is a Cross-Site Scripting (XSS) vulnerability in the 'update user' and 'delete user' functionalities in settings/users.php in EPSON EPS TSE Server 8 (21.0.11).
What is the severity of CVE-2020-28930?
The severity of CVE-2020-28930 is medium with a CVSS score of 5.4.
How does CVE-2020-28930 affect EPSON EPS TSE Server 8?
CVE-2020-28930 allows an authenticated attacker to inject a JavaScript payload in the user management page of EPSON EPS TSE Server 8 (21.0.11) that is executed by an administrator.
How can I fix CVE-2020-28930?
To fix CVE-2020-28930, apply the latest firmware update provided by EPSON for EPS TSE Server 8 (21.0.11) to address the Cross-Site Scripting (XSS) vulnerability.
Where can I find more information about CVE-2020-28930?
More information about CVE-2020-28930 can be found at the following reference: https://blog.bssi.fr/multiple-vulnerabilities-within-epson-eps-tse-server-8/#vulnerability-2