CVE-2020-35121: High severity keysight Database Connector Confluence vulnerability
Published Dec 15, 2020
·Updated
An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could insert arbitrary JavaScript into saved macro parameters that would execute when a user viewed a page with that instance of the macro.
Affected Software
1 affected component
keysight Database Connector Confluence<1.5.0
Event History
Dec 15, 2020
CVE Published
via MITRE·10:07 PM
Data Sourced
via MITRE·10:07 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-35121?
CVE-2020-35121 is considered a medium-severity vulnerability.
2
How do I fix CVE-2020-35121?
To fix CVE-2020-35121, upgrade the Keysight Database Connector plugin to version 1.5.0 or later.
3
Who is affected by CVE-2020-35121?
CVE-2020-35121 affects users of the Keysight Database Connector plugin for Confluence versions prior to 1.5.0.
4
What type of vulnerability is CVE-2020-35121?
CVE-2020-35121 is a cross-site scripting (XSS) vulnerability.
5
What can attackers do with CVE-2020-35121?
Attackers can insert arbitrary JavaScript into the macro parameters that will execute when viewed by other users.