First published: Thu Jun 25 2020(Updated: )
SecureAuth.aspx in SecureAuth IdP 9.3.0 suffers from a client-side template injection that allows for script execution, in the same manner as XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Secureauth Secureauth Identity Provider | =9.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-9437 is rated as a high severity vulnerability due to its potential for client-side template injection, enabling script execution.
To remediate CVE-2020-9437, upgrade SecureAuth IdP to a version beyond 9.3.0 where the vulnerability is patched.
CVE-2020-9437 affects users of SecureAuth IdP version 9.3.0.
CVE-2020-9437 is classified as a client-side template injection vulnerability.
Yes, CVE-2020-9437 can lead to unauthorized script execution, similar to cross-site scripting (XSS) attacks.