First published: Mon Nov 16 2020(Updated: )
Stored cross-site scripting vulnerability in XooNIps 3.49 and earlier allows remote authenticated attackers to inject arbitrary script via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Riken Xoonips | <=3.49 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5663 is a stored cross-site scripting vulnerability in XooNIps 3.49 and earlier.
CVE-2020-5663 allows remote authenticated attackers to inject arbitrary script via unspecified vectors, potentially leading to cross-site scripting attacks.
CVE-2020-5663 has a severity rating of medium with a CVSS score of 5.4.
To fix CVE-2020-5663, it is recommended to update XooNIps to a version later than 3.49.
You can find more information about CVE-2020-5663 at the following references: [Link 1](https://jvn.jp/en/vu/JVNVU92053563/index.html), [Link 2](https://xoonips.osdn.jp/modules/news/index.php?page=article&storyid=13).