CVE-2020-8960: XSS
Published Feb 20, 2020
·Updated
Western Digital mycloud.com before Web Version 2.2.0-134 allows XSS.
Affected Software
1 affected component
WesternDigital Mycloud.com<2.2.0-134
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
western-digital mycloud.comto a version that resolves this vulnerability.Fixed in 2.2.0-134
Event History
Feb 20, 2020
CVE Published
via MITRE·10:03 PM
Data Sourced
via MITRE·10:03 PM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-8960?
CVE-2020-8960 is classified as a medium severity vulnerability due to its potential for XSS attacks.
2
How do I fix CVE-2020-8960?
To fix CVE-2020-8960, upgrade your Western Digital MyCloud.com to version 2.2.0-134 or higher.
3
What types of attacks does CVE-2020-8960 allow?
CVE-2020-8960 allows for cross-site scripting (XSS) attacks, enabling the injection of malicious scripts.
4
Which versions of MyCloud.com are affected by CVE-2020-8960?
CVE-2020-8960 affects all versions of MyCloud.com prior to 2.2.0-134.
5
Who is affected by CVE-2020-8960?
Users of the Western Digital MyCloud.com service prior to version 2.2.0-134 are potentially affected by CVE-2020-8960.